Worm

Worm.Win32.Vobfus.dexi (file analysis)

Malware Removal

The Worm.Win32.Vobfus.dexi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.dexi virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm.Win32.Vobfus.dexi?


File Info:

name: 80D5C793777F17FD19D1.mlw
path: /opt/CAPEv2/storage/binaries/55b71c34761fc95c42ce48fb315783ebd748ae0c540449d88b99668047e7985f
crc32: 65E935B6
md5: 80d5c793777f17fd19d1ce9f3606ca7f
sha1: 833043a324388d18b65e1f5136c46086f6888a4d
sha256: 55b71c34761fc95c42ce48fb315783ebd748ae0c540449d88b99668047e7985f
sha512: 3828121cb3f22a313fd7d2ae82529dfbfa4cece67a8ff667f5d7b7238511ca16956caa3bd75018c2a5ecafc56b06de6b269b10651ccf67c236250742caf725aa
ssdeep: 6144:idSaKl/9f8AbGcdeoDW+/OWtb9yOPmeAVbfP1r4riA7AroW+nYaFyzf/H551Fjme:iYx/9UtO2TW00UM5AEPoViJAndeyCg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14564D176ADA02939F92784B1691983862C0E1E7B1746FC6BA3D0776474B05E3B6F031F
sha3_384: ba5de8ff8db6e68b3ee33971000e93e1e01303c1185b95f6e44665f2529a7968a628a95f70fe08823e45efe0937fb934
ep_bytes: 6898404000e8eeffffff000050000000
timestamp: 1997-03-21 11:25:45

Version Info:

ProductName:
FileVersion:
:

Worm.Win32.Vobfus.dexi also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Barys.268
ClamAVWin.Trojan.Vobfus-6
FireEyeGeneric.mg.80d5c793777f17fd
CAT-QuickHealTrojan.Beebone.D
ALYacGen:Variant.Barys.268
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.3777f1
BaiduWin32.Trojan.VBObfus.f
VirITTrojan.Win32.Zyx.JK
CyrenW32/Vobfus.AD.gen!Eldorado
SymantecW32.SillyFDC
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.AUB
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.dexi
BitDefenderGen:Variant.Barys.268
NANO-AntivirusTrojan.Win32.VB.rilqt
SUPERAntiSpywareTrojan.Agent/Gen-Ursnif
AvastWin32:VB-ACAZ [Trj]
TACHYONTrojan/W32.VB-Agent.311296.BT
EmsisoftGen:Variant.Barys.268 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.VbCrypt.81
VIPREGen:Variant.Barys.268
TrendMicroWORM_VOBFUS.SMJA
McAfee-GW-EditionBehavesLike.Win32.VBObfus.fm
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-W
IkarusWorm.Win32.Vobfus
GDataGen:Variant.Barys.268
JiangminTrojan/Vbobf.b
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.VB.AUA@4o7zkg
ArcabitTrojan.Barys.268
ViRobotTrojan.Win32.A.VB.311296.D
ZoneAlarmWorm.Win32.Vobfus.dexi
MicrosoftTrojan:Win32/Otran!gmb
GoogleDetected
AhnLab-V3Trojan/Win.VB.R558885
Acronissuspicious
McAfeeGeneric VB.kk
MAXmalware (ai score=81)
VBA32BScope.Trojan.VB.Onechki
MalwarebytesGeneric.Worm.AutoRun.DDS
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMJA
RisingTrojan.VBEx!1.99EE (CLASSIC)
YandexTrojan.GenAsa!lh3wojJu4pE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
BitDefenderThetaGen:NN.ZevbaF.36662.tm0@aiWcFyci
AVGWin32:VB-ACAZ [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm.Win32.Vobfus.dexi?

Worm.Win32.Vobfus.dexi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment