Worm

What is “Worm.Win32.Vobfus.aiha”?

Malware Removal

The Worm.Win32.Vobfus.aiha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.aiha virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.Vobfus.aiha?


File Info:

name: 67EA54BFC8A58C81377F.mlw
path: /opt/CAPEv2/storage/binaries/a121d7da77fb1bdd014f04af80346b73a224f8c4a2867c48f47f9dc0aa9c2fea
crc32: 279DF1F9
md5: 67ea54bfc8a58c81377f30081e9f2718
sha1: bcbef146b524a4ddc8d468618f0a7d3fa9fb1c3b
sha256: a121d7da77fb1bdd014f04af80346b73a224f8c4a2867c48f47f9dc0aa9c2fea
sha512: e52b43f3d5fc35230c4ae0624bbe12fd3a997f56f55fc509ab2a34d6388c63aba5722a48126ecd669f4e454313f7d504a6881ed1326a1fa451f7c2482125778e
ssdeep: 1536:7/uvDaQCqG84caEz0+nCsNAhz74yWzVaAgGV4VE:qDaF84vz74yOsAgG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17B93D72FBE48A064D52AA13636FBCBEA14577C185B3BC1872614F7BE6DA7F001C19607
sha3_384: 58efa9fd74c34ac0a45f2fde510a55f22f64f7795dc6ca328af5f2d790563634f3ea5122b6b357899d2d6c6e89ec5245
ep_bytes: 6878124000e8eeffffff000000000000
timestamp: 2012-10-09 18:48:14

Version Info:

Translation: 0x0409 0x04b0
ProductName: mericarp
FileVersion: 2.96
ProductVersion: 2.96
InternalName: Adagerebbe
OriginalFilename: Adagerebbe.exe

Worm.Win32.Vobfus.aiha also known as:

BkavW32.AIDetectMalware
AVGWin32:VB-AERT [Trj]
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner1.27508
MicroWorld-eScanGen:Variant.Barys.2644
FireEyeGeneric.mg.67ea54bfc8a58c81
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.mt
McAfeeW32/Autorun.worm.sl
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.fc8a58
BitDefenderThetaAI:Packer.F469B28D20
VirITWorm.Win32.VB.JK
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/Pronny.FK
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:VB-AERT [Trj]
ClamAVWin.Trojan.VB-1595
KasperskyWorm.Win32.Vobfus.aiha
BitDefenderGen:Variant.Barys.2644
NANO-AntivirusTrojan.Win32.VB.cojapo
RisingWorm.Vobfus!8.10E (TFE:3:lcEAeq79k0H)
EmsisoftGen:Variant.Barys.2644 (B)
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Worm.Pronny.dq
VIPREGen:Variant.Barys.2644
TrendMicroWORM_VOBFUS.SMIV
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-AC
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=83)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus.JN
XcitiumTrojWare.Win32.Pronny.EE@4qvpy8
ArcabitTrojan.Barys.DA54
ZoneAlarmWorm.Win32.Vobfus.aiha
GDataGen:Variant.Barys.2644
VaristW32/Vobfus.AT.gen!Eldorado
AhnLab-V3Trojan/Win32.Menti.R27300
Acronissuspicious
TACHYONWorm/W32.Vobfus.90112.C
VBA32Worm.VBNA
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMIV
TencentWorm.Win32.Vobfus.hv
IkarusVirus.Win32.VB
MaxSecureTrojan.Malware.9870406.susgen
FortinetW32/Injector.ADYA!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudWorm:Win/Vobfus.1d85df10

How to remove Worm.Win32.Vobfus.aiha?

Worm.Win32.Vobfus.aiha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment