Worm

What is “Worm.Win32.Vobfus.dges”?

Malware Removal

The Worm.Win32.Vobfus.dges is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.dges virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.Vobfus.dges?


File Info:

name: 66671B195839FDCCCE1E.mlw
path: /opt/CAPEv2/storage/binaries/1e918e55d0155316d13f10b22498423ab60c1ebccde7b3946cf5742e397fc5be
crc32: 28EC8737
md5: 66671b195839fdccce1ece9b4fe1bc19
sha1: 9d1764d6eafbdd00bb4861862f3e742a03034d6b
sha256: 1e918e55d0155316d13f10b22498423ab60c1ebccde7b3946cf5742e397fc5be
sha512: b1b2983b4e1ef1ed786cbc7e526e7feedae81c4a13aad83dae2e395ea6dec1e045fd99a301bd1a5662e31859feee9d28d56ad226433e58ce4ad94045930ea5b3
ssdeep: 6144:Xm7Bqr3iNvcMI55xjg4+tU1pZ5UdxIOTQMyHct1FHRQo1:27BQMULfjg4+tU1pZ5UdxIOTQMyHS1FZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19D24B27AA210977AE025DCF5E8698398015D6D3B19E4E407FBC22B19F5F0AFE9231353
sha3_384: 2049c71707743c69b148de9c0f924fd644c59f4f104d352096bf4ce9324b4109ca072a05787bf19d1bc124198e9db5df
ep_bytes: 68e8384000e8f0ffffff000000000000
timestamp: 1996-08-12 18:20:09

Version Info:

Translation: 0x0409 0x04b0
ProductName: jzYAMRDq
FileVersion: 1.00
ProductVersion: 1.00
InternalName: ZPBIdy
OriginalFilename: ZPBIdy.exe

Worm.Win32.Vobfus.dges also known as:

BkavW32.AIDetectMalware
DrWebTrojan.VbCrypt.81
MicroWorld-eScanGen:Variant.Barys.2490
SkyhighBehavesLike.Win32.Generic.dm
McAfeeVBObfus.cu
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZevbaF.36802.oq0@amcvN3ci
VirITTrojan.Win32.Zyx.HM
SymantecW32.Changeup!gen15
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.AQW
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMAB
ClamAVWin.Trojan.Vobfus-3
KasperskyWorm.Win32.Vobfus.dges
BitDefenderGen:Variant.Barys.2490
NANO-AntivirusTrojan.Win32.VB.rilqn
SUPERAntiSpywareTrojan.Agent/Gen-FakeAlert[Mx]
AvastWin32:VB-AAVP [Trj]
TencentWorm.Win32.Vobfus.n
EmsisoftGen:Variant.Barys.2490 (B)
GoogleDetected
F-SecureTrojan.TR/VB.Agent.aztqb
BaiduWin32.Worm.Pronny.d
VIPREGen:Variant.Barys.2490
TrendMicroWORM_VOBFUS.SMAB
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.66671b195839fdcc
SophosMal/VBCheMan-B
SentinelOneStatic AI – Malicious PE
VaristW32/Vobfus.BE.gen!Eldorado
AviraTR/VB.Agent.aztqb
MAXmalware (ai score=83)
Antiy-AVLVirus/Win64.Expiro.rsrc
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumTrojWare.Win32.Diple.EMIB@4pez3w
ArcabitTrojan.Barys.D9BA
ViRobotTrojan.Win32.A.VB.229376.D
ZoneAlarmWorm.Win32.Vobfus.dges
GDataGen:Variant.Barys.2490
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VB.R19758
Acronissuspicious
VBA32BScope.Trojan.VBCR.2512
ALYacGen:Variant.Barys.2490
TACHYONWorm/W32.Vobfus.229376
Cylanceunsafe
PandaTrj/Genetic.gen
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!2quyvPaWvHA
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.AZGU!tr
AVGWin32:VB-AAVP [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Vobfus.305c092c

How to remove Worm.Win32.Vobfus.dges?

Worm.Win32.Vobfus.dges removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment