Worm

How to remove “Worm.Win32.Vobfus.cxya”?

Malware Removal

The Worm.Win32.Vobfus.cxya is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.cxya virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.Vobfus.cxya?


File Info:

name: 48170AA89630DD477A97.mlw
path: /opt/CAPEv2/storage/binaries/37df5e1729c0275a255d4344bf7a9a89ecbe205be75b772251b212af2a32c291
crc32: B85BE14B
md5: 48170aa89630dd477a97188dfa08da8b
sha1: bda4060d30c52d04b6390352178891ac73a350cf
sha256: 37df5e1729c0275a255d4344bf7a9a89ecbe205be75b772251b212af2a32c291
sha512: 06924c9cc5d388e685ae1812cbf58411709220130e182c58b046ce7291e271c7abb3bf02a7ff113ad0ebddbff7fa29f8879ac168194b8bf6053430a7d6884b84
ssdeep: 3072:JypdVAXY71idPAaRELGzMshNXTDFE+7jF6XTjCx:JypzAY+ocqFshNTDT756XT4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EF0450256240E23DF020DAFD775442964DA86EB2D1D2A81BE2F8FB1137F4B5653B07A3
sha3_384: f8503b4ec56e36988b824d09b7957b360c8592f94156d0c1104a9385897c8e72552d1425414ac046e710fbb3d5a4591e
ep_bytes: 68cc484000e8eeffffff000058000000
timestamp: 2012-06-19 07:41:52

Version Info:

Translation: 0x0409 0x04b0
Comments: Papillitis
CompanyName: Protostegidae Ejection
FileDescription: Fuye Actinocutitis
LegalCopyright: Seymour pseudolateral Reichsland
LegalTrademarks: Inexhaustibly palingenic
ProductName: Somatization ripiegasti
FileVersion: 6.05
ProductVersion: 6.05
InternalName: mzackzam
OriginalFilename: mzackzam.exe

Worm.Win32.Vobfus.cxya also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Symmi.769
ClamAVWin.Trojan.Changeup-6169544-0
FireEyeGeneric.mg.48170aa89630dd47
CAT-QuickHealTrojan.Beebone.D
McAfeeGenDownloader.oq
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.89630d
BaiduWin32.Trojan.VBObfus.f
VirITTrojan.Win32.Generic.ABKN
CyrenW32/Vobfus.BE.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.AWV
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.cxya
BitDefenderGen:Variant.Symmi.769
NANO-AntivirusTrojan.Win32.Vobfus.ewqiln
SUPERAntiSpywareTrojan.Agent/Gen-Vban
AvastWin32:VB-ADKF [Trj]
TencentWorm.Win32.Vobfus.n
Ad-AwareGen:Variant.Symmi.769
TACHYONWorm/W32.Vobfus.184320.C
EmsisoftGen:Variant.Symmi.769 (B)
ComodoWorm.Win32.VB.AUA@4o7zkg
DrWebTrojan.VbCrypt.60
VIPREGen:Variant.Symmi.769
TrendMicroWORM_VOBFUS.SMIV
McAfee-GW-EditionGenDownloader.oq
Trapminemalicious.high.ml.score
SophosML/PE-A + W32/Autorun-BXZ
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Vbobf.b
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASBOL.5
MicrosoftPWS:Win32/Zbot!ml
ViRobotWorm.Win32.A.WBNA.184320.J
ZoneAlarmWorm.Win32.WBNA.ipa
GDataGen:Variant.Symmi.769
GoogleDetected
AhnLab-V3Worm/Win32.WBNA.R28275
BitDefenderThetaAI:Packer.4E1D8AA220
ALYacGen:Variant.Symmi.769
MAXmalware (ai score=86)
VBA32BScope.Trojan.VB.Onechki
MalwarebytesVobfus.Worm.Evasion.DDS
TrendMicro-HouseCallWORM_VOBFUS.SMIV
RisingWorm.Autorun!8.50 (TFE:3:ThNcPkzgh1O)
YandexTrojan.GenAsa!voQa7MUqIZQ
IkarusBackdoor.VB
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-ADKF [Trj]
PandaW32/Vobfus.GEW.worm
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm.Win32.Vobfus.cxya?

Worm.Win32.Vobfus.cxya removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment