Worm

Worm.Win32.Vobfus.dfgo malicious file

Malware Removal

The Worm.Win32.Vobfus.dfgo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.dfgo virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm.Win32.Vobfus.dfgo?


File Info:

name: F5B59A98D1793FAFE9DB.mlw
path: /opt/CAPEv2/storage/binaries/fd8112ccf0b7cc1ee7c0ef59b30673c731ce0eeb03f6baef38a8ab3605bf1ceb
crc32: 2B7EF65A
md5: f5b59a98d1793fafe9db32870be65947
sha1: 613b169956b57ad6d2a1e70397b5dbaa134298a8
sha256: fd8112ccf0b7cc1ee7c0ef59b30673c731ce0eeb03f6baef38a8ab3605bf1ceb
sha512: ce45aa1f847774554575fe1fd0c40eaf5a8d9fb4ddf61552fe7eb2287af5a870f4dc0ca71b96619f4447424b2fe20d02a9665422c640c8748344ad65c24b70d9
ssdeep: 3072:rkW/vzoFkT/Ozb1/7Vc1tdjZQQLnQhhyBZ8Irfdaqebssot7rFVtWzdbcGBXY6:rPMK2bVMJuQ0hhynfdaJqNrtWzCql
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19D5494157290F72ED560C5F03A4682A0687E9C7364E56807FBC13F6A77B1DA7E221723
sha3_384: ba6225843a503f7b0255fec4e1da506a797d2718ba36a9ae281aa9d0fea31d16afa1cd79eb6a4a0d8bef9dbc05e0caef
ep_bytes: 68084a4000e8eeffffff000000000000
timestamp: 2012-01-09 17:04:17

Version Info:

Translation: 0x0409 0x04b0
ProductName: ASdURauBm
FileVersion: 1.00
ProductVersion: 1.00
InternalName: ukLIaMhPVM
OriginalFilename: ukLIaMhPVM.exe

Worm.Win32.Vobfus.dfgo also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Chinky.7
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.eq
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
BaiduWin32.Trojan.Inject.n
VirITTrojan.Win32.SHeur4.MYN
SymantecW32.Changeup!gen15
Elasticmalicious (high confidence)
ESET-NOD32Win32/Pronny.AC
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMAB
ClamAVWin.Trojan.Vobfus-70360
KasperskyWorm.Win32.Vobfus.dfgo
BitDefenderGen:Variant.Chinky.7
NANO-AntivirusTrojan.Win32.Diple.cinarz
AvastWin32:AutoRun-CMS [Trj]
TencentWorm.Win32.Vobfus.kv
TACHYONWorm/W32.Vobfus.286720
EmsisoftGen:Variant.Chinky.7 (B)
F-SecureTrojan.TR/Otran.ammy
DrWebTrojan.VbCrypt.81
VIPREGen:Variant.Chinky.7
TrendMicroWORM_VOBFUS.SMAB
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.f5b59a98d1793faf
SophosMal/ZboCheMan-B
IkarusTrojan.Win32.Diple
WebrootW32.Trojan.Diple.Gen
GoogleDetected
AviraTR/Otran.ammy
VaristW32/Vobfus.Z.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.999
MicrosoftWorm:Win32/Vobfus!pz
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Chinky.7
ViRobotTrojan.Win32.A.Diple.286720.B
ZoneAlarmWorm.Win32.Vobfus.dfgo
GDataGen:Variant.Chinky.7
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Diple.R19483
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36804.rm0@a8u@1Bni
MAXmalware (ai score=82)
VBA32BScope.Trojan.Diple
Cylanceunsafe
PandaGeneric Malware
ZonerTrojan.Win32.85665
RisingWorm.VobfusEx!1.99DC (KTSE)
YandexTrojan.GenAsa!dzZglQkmYBs
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Diple.EJQE!tr
AVGWin32:AutoRun-CMS [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Vobfus.b6444d0a

How to remove Worm.Win32.Vobfus.dfgo?

Worm.Win32.Vobfus.dfgo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment