Worm

Worm.VobfusVMF.S28606066 removal tips

Malware Removal

The Worm.VobfusVMF.S28606066 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.VobfusVMF.S28606066 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm.VobfusVMF.S28606066?


File Info:

name: 5B4BFA5A546D2FDFEAD8.mlw
path: /opt/CAPEv2/storage/binaries/28b51ad59ab51caaa2d4b500af19262d0cb172275821e209bba0124810dd9fd7
crc32: 44CD33E4
md5: 5b4bfa5a546d2fdfead8fb5a610b890a
sha1: 90b2dedd5ce4b886ef1cfe026aa02f31a5880b69
sha256: 28b51ad59ab51caaa2d4b500af19262d0cb172275821e209bba0124810dd9fd7
sha512: f58218fce0e1ed9e9d3d27ad6b7632aca3ffcf89466c3b506caf1a3cdc5601852200f74971790449cd0536b893b0aa4e8cafb7d441c6e95e1111f2bb88b87748
ssdeep: 6144:TnWWHn3oBlwEL2wKnvmb7/D26OzRnH/QUw3LsFItNkVFZmJuFxCwG:Tnrn3oBlwyKnvmb7/D26itwbsFgNk0JR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11324B512BE15A02BE14284F06A7CA3563C2D2D7A27A0FC0777817F2866B5597B8F075F
sha3_384: c7fc507f21da2f1695ce65c841a00a10a50a57d1bb37c8d0bfb49c79d86eeb7d3ddb265c36d8cb706a5d7369e5df1ed3
ep_bytes: 68643d4000e8eeffffff000000000000
timestamp: 2011-11-14 20:31:01

Version Info:

ProductName:
FileVersion: 1.00
ProductVersion: 1.00
InternalName:
OriginalFilename:

Worm.VobfusVMF.S28606066 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.VBInject.11
CAT-QuickHealWorm.VobfusVMF.S28606066
ALYacGen:Variant.VBInject.11
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.a546d2
BaiduWin32.Worm.Autorun.l
VirITTrojan.Win32.Zyx.FU
SymantecW32.Changeup
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
AlibabaWorm:Win32/vobfus.f2ec
NANO-AntivirusTrojan.Win32.Diple.crgjhf
TACHYONWorm/W32.Vobfus.225280.E
SophosMal/VBCheMan-J
F-SecureTrojan.TR/Otran.ansn
DrWebTrojan.VbCrypt.77
VIPREGen:Variant.VBInject.11
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.VBInject.11 (B)
IkarusTrojan.Win32.Diple
AviraTR/Otran.ansn
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.VBInject.11
SUPERAntiSpywareTrojan.Agent/Gen-Autogen
ZoneAlarmWorm.Win32.Vobfus.efgw
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R16322
DeepInstinctMALICIOUS
BitDefenderThetaGen:NN.ZevbaF.36802.nm0@aeyHVSfi
MAXmalware (ai score=85)
Cylanceunsafe
TencentWorm.Win32.Vobfus.n
YandexTrojan.GenAsa!HV5DVMK3sbU
SentinelOneStatic AI – Malicious PE
FortinetW32/Diple.EJQE!tr
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan.Win.UnkAgent

How to remove Worm.VobfusVMF.S28606066?

Worm.VobfusVMF.S28606066 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment