Worm

What is “Worm.Win32.Vobfus.dfqk”?

Malware Removal

The Worm.Win32.Vobfus.dfqk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.dfqk virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.Vobfus.dfqk?


File Info:

name: 920FC7642D0F6044AA8D.mlw
path: /opt/CAPEv2/storage/binaries/f85ef0514b17a62602fc0e8bac9c33ce9cddf6bd701997f0202cf57862d3d034
crc32: 16D374F1
md5: 920fc7642d0f6044aa8d453823c755f3
sha1: b0cc5856bb8915a282115885c8180980a0136d82
sha256: f85ef0514b17a62602fc0e8bac9c33ce9cddf6bd701997f0202cf57862d3d034
sha512: 3fc90c3aa9b7aa7b67383171ecba5c712c7ca1a86ec14912851ebc48619026f6d04dc5c22b020c0a13d3b6dd4952596099e536471415aba2adbf82fd8a6e0ee5
ssdeep: 3072:PMly5apYFWWYUczAveWBBDJDuviDO2lf4oQZiEok:oCapYFDYe2gpxuvia2lhW5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ABE3931A7691F37AC414C6F83D1A83A0A079EC3225E26C17F7C25B1A76F1D9BD220763
sha3_384: 5c04d02a3d143d23f81af05b0262734327cb279311eda8d2ab2ba8badd787452f2198dad17cac038387830c53dd255ac
ep_bytes: 6880334000e8eeffffff000000000000
timestamp: 2011-09-19 14:47:29

Version Info:

Translation: 0x0409 0x04b0
ProductName: emAkahzjYlbmFMyncllt
FileVersion: 1.00
ProductVersion: 1.00
InternalName: sojrljpiUgpmsy
OriginalFilename: sojrljpiUgpmsy.exe

Worm.Win32.Vobfus.dfqk also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.luev
MicroWorld-eScanGen:Variant.VBInject.11
ClamAVWin.Trojan.Changeup-6169544-0
FireEyeGeneric.mg.920fc7642d0f6044
CAT-QuickHealTrojan.Vobfus.gen
ALYacGen:Variant.VBInject.11
Cylanceunsafe
VIPREGen:Variant.VBInject.11
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaMalware:Win32/km_2ff3a.None
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.42d0f6
BaiduWin32.Worm.Pronny.d
VirITTrojan.Win32.Generic.CNVC
CyrenW32/Vobfus.V.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.ALU
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.dfqk
BitDefenderGen:Variant.VBInject.11
NANO-AntivirusTrojan.Win32.WBNA.covkcc
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ABDC [Drp]
TencentTrojan.Win32.Koobface.p
TACHYONWorm/W32.Vobfus.155648.E
EmsisoftGen:Variant.VBInject.11 (B)
F-SecureTrojan.TR/Diple.bcfwac
DrWebTrojan.VbCrypt.60
TrendMicroWORM_VOBFUS.SMHE
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-T
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.VBInject.11
AviraTR/Diple.bcfwac
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.VBInject.11
ZoneAlarmWorm.Win32.Vobfus.dfqk
MicrosoftWorm:Win32/Vobfus.gen!N
GoogleDetected
AhnLab-V3Trojan/Win32.Diple.R13793
McAfeeVBObfus.bn
MAXmalware (ai score=80)
VBA32BScope.Trojan.VB.Diple.01583
MalwarebytesMalware.AI.4076785272
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMHE
RisingWorm.Vobfus!1.99C7 (CLASSIC)
YandexTrojan.GenAsa!sWk+PuQCBtc
IkarusWin32.Outbreak
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.CNE!worm
BitDefenderThetaAI:Packer.9C9A1D8320
AVGWin32:VB-ABDC [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm.Win32.Vobfus.dfqk?

Worm.Win32.Vobfus.dfqk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment