Worm

How to remove “Worm.Win32.Vobfus.bfvm”?

Malware Removal

The Worm.Win32.Vobfus.bfvm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.bfvm virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm.Win32.Vobfus.bfvm?


File Info:

name: F5E2D504E9504D7DEB23.mlw
path: /opt/CAPEv2/storage/binaries/2a301d196a7883956b6e16ca1cddd23098af096523fc83dcfda47dfac5de98f6
crc32: 5C7D9EB6
md5: f5e2d504e9504d7deb23e97c969d3bf2
sha1: a9dfc94cb999bc02989369063588cf06df271a80
sha256: 2a301d196a7883956b6e16ca1cddd23098af096523fc83dcfda47dfac5de98f6
sha512: b276e2b1a24c25cb06ddafe6007b60097e21744999297e2bd62669b7620ff2fb577b8ac21d9370f7c7b782877a158f6cc2a29db34500a4b0670f2616c2ddab0b
ssdeep: 6144:dJn/iyc5mFpvMTuGSouFQIlzBI1Iq3Fdrj6DUKSpFw+x:L/Pc5mFpxzBI1X3Fdrj6DUKSpx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12824D93562C0FB3AE1A2C7F439D983925429AC3234B5680BF7C11B3577E5E97962072B
sha3_384: e53d6b1421c1d39bbab3cb4407c3e6fbff6a0ecb660dfacf2b076e57defcabd3d4363cd1becd8a8e57e348c1482e8f1f
ep_bytes: 688c3a4000e8f0ffffff000000000000
timestamp: 2012-09-19 18:17:15

Version Info:

Translation: 0x0409 0x04b0
ProductName: Cephalalgy
FileVersion: 0.94
ProductVersion: 0.94
InternalName: enterotome
OriginalFilename: enterotome.exe

Worm.Win32.Vobfus.bfvm also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebTrojan.VbCrypt.60
MicroWorld-eScanGen:Variant.Barys.950
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeGenDownloader.rv
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderThetaGen:NN.ZevbaF.36804.nm0@auzl3Xhi
VirITTrojan.Win32.Zyx.OD
Elasticmalicious (high confidence)
ESET-NOD32Win32/Pronny.EH
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SM02
ClamAVWin.Trojan.Vobfus-28
KasperskyWorm.Win32.Vobfus.bfvm
BitDefenderGen:Variant.Barys.950
NANO-AntivirusTrojan.Win32.WBNA.cihuhh
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:VB-AENC [Trj]
TencentWorm.Win32.Vobfus.co
EmsisoftGen:Variant.Barys.950 (B)
GoogleDetected
F-SecureTrojan.TR/Barys.U
BaiduWin32.Trojan.VBObfus.f
VIPREGen:Variant.Barys.950
TrendMicroWORM_VOBFUS.SM02
FireEyeGeneric.mg.f5e2d504e9504d7d
SophosMal/SillyFDC-W
SentinelOneStatic AI – Malicious PE
JiangminWorm/Vobfus.ilf
WebrootTrojan.Win32.Diple
VaristW32/Vobfus.BE.gen!Eldorado
AviraTR/Barys.U
MAXmalware (ai score=85)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus
XcitiumTrojWare.Win32.Pronny.EE@4qvpy8
ArcabitTrojan.Barys.950
ViRobotWorm.Win32.A.Vobfus.225280
ZoneAlarmWorm.Win32.Vobfus.bfvm
GDataGen:Variant.Barys.950
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Vobfus.R36953
VBA32BScope.Trojan.Diple
ALYacGen:Variant.Barys.950
TACHYONWorm/W32.Vobfus.225280.C
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
RisingMalware.FakeFolder/ICON!1.6AC4 (CLASSIC)
YandexTrojan.GenAsa!vmHZB8087iQ
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.11636831.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-AENC [Trj]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.3e4a4b99

How to remove Worm.Win32.Vobfus.bfvm?

Worm.Win32.Vobfus.bfvm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment