Worm

Worm.Win32.Vobfus.dfct information

Malware Removal

The Worm.Win32.Vobfus.dfct is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.dfct virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.Vobfus.dfct?


File Info:

name: 6A603CADF7261FC0D6E5.mlw
path: /opt/CAPEv2/storage/binaries/f73616acacd4260d77aefca22d06507b487b9deb4aed2e38e6baaed47d8b6c76
crc32: 8E4C79D7
md5: 6a603cadf7261fc0d6e543b723e7d8cf
sha1: b91e77753e38e09afc5462bd8aa916dc525237f7
sha256: f73616acacd4260d77aefca22d06507b487b9deb4aed2e38e6baaed47d8b6c76
sha512: f6dd815329b60153590821dc845052f679b8d00f49da11d5b2c17e40b8377b36d4f69df60048df46b600d6b5a62cfcf160c17f9b6b65257db0367b76edf9709b
ssdeep: 3072:DU0nydhQdimOZAksTCPkix7Fe7dEN8EXgNqf5cTrWi6ei2uiTbtTmH8Fe90p06tG:40Ti+bYJFsE0NMCP6wJYj8t/xg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19254D7157290F72ED525C6F03A5A83A0557EEC3225B16807FBD22F2A33B1D5BE261723
sha3_384: a5d5d33eda5762761b90be9a1c36324d44ee077fd201e4bd450986d86af7306c2fe6a52f7f47e026f2676f1bb137a67d
ep_bytes: 6840444000e8f0ffffff000048000000
timestamp: 2010-05-17 01:48:41

Version Info:

Translation: 0x0409 0x04b0
ProductName: FdigvSm
FileVersion: 1.00
ProductVersion: 1.00
InternalName: mBYSplWd
OriginalFilename: mBYSplWd.exe

Worm.Win32.Vobfus.dfct also known as:

BkavW32.AIDetectMalware
AVGWin32:AutoRun-CMZ [Trj]
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.95023
FireEyeGeneric.mg.6a603cadf7261fc0
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.Generic.dm
McAfeeVBObfus.eq
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.df7261
BaiduWin32.Trojan.Inject.n
VirITTrojan.Win32.Generic.BGME
SymantecW32.Changeup!gen15
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.AQP
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Vobfus-70360
KasperskyWorm.Win32.Vobfus.dfct
BitDefenderTrojan.GenericKDZ.95023
NANO-AntivirusTrojan.Win32.WBNA.cinawp
AvastWin32:AutoRun-CMZ [Trj]
TACHYONWorm/W32.Vobfus.294912.E
EmsisoftTrojan.GenericKDZ.95023 (B)
F-SecureTrojan.TR/VB.abn
DrWebWorm.Siggen.10220
VIPRETrojan.GenericKDZ.95023
TrendMicroWORM_VOBFUS.SMAB
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-AC
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Diple.ahjh
VaristW32/Vobfus.Z.gen!Eldorado
AviraTR/VB.abn
Antiy-AVLVirus/Win64.Expiro.rsrc
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumWorm.Win32.VB.AUA@4o7zkg
ArcabitTrojan.Generic.D1732F
ViRobotTrojan.Win32.A.Diple.294912.X
ZoneAlarmWorm.Win32.Vobfus.dfct
GDataTrojan.GenericKDZ.95023
GoogleDetected
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36802.sq0@aWrHACii
ALYacTrojan.GenericKDZ.95023
MAXmalware (ai score=82)
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMAB
RisingWorm.VobfusEx!1.99D9 (CLASSIC)
YandexTrojan.GenAsa!1iZFKuhiRA4
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Diple.EJQE!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan:Win/Vobfus.d90148dc

How to remove Worm.Win32.Vobfus.dfct?

Worm.Win32.Vobfus.dfct removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment