Worm

What is “Worm.Win32.Vobfus.ddpy”?

Malware Removal

The Worm.Win32.Vobfus.ddpy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.ddpy virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm.Win32.Vobfus.ddpy?


File Info:

name: 86B73C9F5A263DEB64D3.mlw
path: /opt/CAPEv2/storage/binaries/333af249cad89f179d1b5c25696c9c186b28700e0b8d6acf8cb063aaa80f2fdd
crc32: BC4422A0
md5: 86b73c9f5a263deb64d39463de5ae51d
sha1: ed46810bccd16c9b26d37de0d99202f4fa8747d0
sha256: 333af249cad89f179d1b5c25696c9c186b28700e0b8d6acf8cb063aaa80f2fdd
sha512: cbe688775f1f3ce1648171732b256b4cd1ef9e173181d8a70c5f71c10a437d6a3405140e94b8e0cbfacb5636c3e5e4d248b6e1dcac018d924fea9ef9ff9c2a85
ssdeep: 3072:Hj47vzQqQ7b4zxMJsSmJMnTQFlKRilqoq6v/:8AqM4zk02qfMot
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1931482397240E33DE411CFF828AAA3A75069AF3515C1A41BF7C26B1975F19A3D220F97
sha3_384: 8d493c98837897e5e3dc1d7523ac19437237db4e3a3d8c98e036c8b1c35ae0504882d16aa75ba202648c9f65d2a1082b
ep_bytes: 68303d4000e8eeffffff000000000000
timestamp: 2012-03-16 06:46:07

Version Info:

FileVersion: 2.30
ProductVersion: 2.30
Translation: 0x0409 0x04b0

Worm.Win32.Vobfus.ddpy also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.VbCrypt.81
MicroWorld-eScanGen:Variant.VBInject.11
FireEyeGeneric.mg.86b73c9f5a263deb
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeVBObfus.ek
MalwarebytesGeneric.Worm.AutoRun.DDS
ZillyaWorm.Vobfus.Win32.1519450
SangforSuspicious.Win32.Save.vb
AlibabaWorm:Win32/Vobfus.112080d6
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderThetaGen:NN.ZevbaF.36802.lm0@aOsW43ei
VirITTrojan.Win32.Zyx.JA
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.ATJ
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMJA
ClamAVWin.Trojan.VB-73692
KasperskyWorm.Win32.Vobfus.ddpy
BitDefenderGen:Variant.VBInject.11
NANO-AntivirusTrojan.Win32.VB.rilpi
SUPERAntiSpywareTrojan.Agent/Gen-Remnat[VB]
AvastWin32:VB-ACAH [Wrm]
TencentWorm.Win32.Vobfus.n
EmsisoftGen:Variant.VBInject.11 (B)
F-SecureWorm.WORM/Vobfus.R.22
BaiduWin32.Trojan.Inject.n
VIPREGen:Variant.VBInject.11
TrendMicroWORM_VOBFUS.SMJA
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-W
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=88)
JiangminTrojan/Vbobf.b
WebrootW32.Worm.R
GoogleDetected
AviraWORM/Vobfus.R.22
VaristW32/Vobfus.BE.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.VBInject.11
ViRobotTrojan.Win32.A.VB.192512.L
ZoneAlarmWorm.Win32.Vobfus.ddpy
GDataGen:Variant.VBInject.11
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.WBNA.R22840
Acronissuspicious
ALYacGen:Variant.VBInject.11
TACHYONWorm/W32.Vobfus.192512.B
VBA32BScope.Trojan.VBKrypt
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
RisingWorm.VobfusEx!1.99DC (CLASSIC)
YandexTrojan.GenAsa!+pILib76z2w
IkarusWorm.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-ACAH [Wrm]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.deed1809

How to remove Worm.Win32.Vobfus.ddpy?

Worm.Win32.Vobfus.ddpy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment