Worm

Worm.Win32.Vobfus.dfbu removal

Malware Removal

The Worm.Win32.Vobfus.dfbu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.dfbu virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm.Win32.Vobfus.dfbu?


File Info:

name: 1BED975D8CA802B2B4A5.mlw
path: /opt/CAPEv2/storage/binaries/2fb66cbee02aa199795b854826c53564ba51f0be40ad4726e4b8f711a1468e8d
crc32: 027B9F0F
md5: 1bed975d8ca802b2b4a5643572dd5d90
sha1: 6120b09f60c8f93a49b2765527b3b2e04f55c501
sha256: 2fb66cbee02aa199795b854826c53564ba51f0be40ad4726e4b8f711a1468e8d
sha512: bc22ff3e6cec3e816c3b00f8f4152e62b7b344c3eb9aa5da63d60ab360dcc9ca04fcfb626924845dae6040d27afd8316e3a1c59fbf034da792851898fc1b652a
ssdeep: 3072:H8GT/sZ5qbLj1w+A3W6xNYa7CgPCmHV1BdHDYqzUnQUoulDC:Hbwqvj1BA7xHCgPCmHV1BdHDYoUZs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17C24C53A7280E73EE521C7F52D9D83A0446D6D3615D1E00BF7C22B1A76F1AE782217A7
sha3_384: 7c23fcbf1598f6990129b50eee5c2f877716f983db4e02e4db9645e79768e6df73755924654f32fe0d0ab04b679d2b0c
ep_bytes: 68e04a4000e8f0ffffff000000000000
timestamp: 2012-03-13 00:22:05

Version Info:

ProductName: XrCLTe
FileVersion: 1.00
ProductVersion: 1.00
Translation: 0x0409 0x04b0

Worm.Win32.Vobfus.dfbu also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.ly6y
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.461870
FireEyeGeneric.mg.1bed975d8ca802b2
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
ALYacGen:Variant.Zusy.461870
MalwarebytesVBObfus.Worm.Spreader.DDS
ZillyaWorm.WBNA.Win32.362789
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderGen:Variant.Zusy.461870
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.f60c8f
BaiduWin32.Trojan.Inject.n
VirITTrojan.Win32.SHeur4.UDL
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.ATD
APEXMalicious
ClamAVWin.Trojan.VB-73686
KasperskyWorm.Win32.Vobfus.dfbu
AlibabaWorm:Win32/Vobfus.1616f495
NANO-AntivirusTrojan.Win32.WBNA.csurql
ViRobotWorm.Win32.A.WBNA.229376.GA
RisingWorm.VobfusEx!1.99DB (CLASSIC)
SophosMal/VBCheMan-B
F-SecureTrojan.TR/Kazy.6063225
DrWebTrojan.VbCrypt.60
VIPREGen:Variant.Zusy.461870
TrendMicroWORM_VOBFUS.SM03
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Zusy.461870 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=100)
JiangminTrojan/Vbobf.b
GoogleDetected
AviraTR/Kazy.6063225
VaristW32/Vobfus.BE.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Zusy.D70C2E
SUPERAntiSpywareTrojan.Agent/Gen-Autorun[VB]
ZoneAlarmWorm.Win32.Vobfus.dfbu
GDataGen:Variant.Zusy.461870
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R64119
Acronissuspicious
McAfeeGeneric VB.kk
TACHYONTrojan/W32.Agent.229376.B
DeepInstinctMALICIOUS
VBA32BScope.Trojan.VB.Onechki
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SM03
TencentWorm.Win32.Vobfus.n
YandexTrojan.GenAsa!vYS1ixIebGo
IkarusTrojan.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
BitDefenderThetaGen:NN.ZevbaF.36792.om0@a0R!7cdi
AVGWin32:VB-ABRQ [Trj]
AvastWin32:VB-ABRQ [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm.Win32.Vobfus.dfbu?

Worm.Win32.Vobfus.dfbu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment