Worm

About “Worm.Win32.Vobfus.dgpv” infection

Malware Removal

The Worm.Win32.Vobfus.dgpv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.dgpv virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.Vobfus.dgpv?


File Info:

name: 29D934E2E27F80B48563.mlw
path: /opt/CAPEv2/storage/binaries/d603a88aa7cf563437e3154f8b9973906f5f4328ba68f618775548a5657f119e
crc32: 8C6B0079
md5: 29d934e2e27f80b48563861eb8acd5e8
sha1: 6a9e5ef4a2a884a395c0ddbf3bed638d82aa9889
sha256: d603a88aa7cf563437e3154f8b9973906f5f4328ba68f618775548a5657f119e
sha512: 097f90faefa3637eaaccf4509a590b4d7300937c1e4394308d1b0914d34585bbd3db2985b1cc2f9266b26e0a5da298015c40d71e755a734bd3c3249ceb971e61
ssdeep: 3072:I0A2afa1Fbn4DpS41Zr8EbjfmNwXl1RgxfGDP8F2dqMOkeuF7SzotBXpZ:Tay1Fz4Dp7R8cA0l1RpLtJj7SkbX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C75484157390FB2DD520C5F03A4683A0A87E9D3264E56803FAC13F6A77B1DABE161727
sha3_384: 1fadaea2fffb691710fd11e9b4aec3d762ed76659db6ac3119e25d56a979c285b799cd3233256dd3cd9c423e39467dfb
ep_bytes: 68e44a4000e8eeffffff000000000000
timestamp: 2012-01-07 18:24:49

Version Info:

Translation: 0x0409 0x04b0
ProductName: aykKRJCE
FileVersion: 1.00
ProductVersion: 1.00
InternalName: SrxlcXxqdv
OriginalFilename: SrxlcXxqdv.exe

Worm.Win32.Vobfus.dgpv also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Chinky.7
ClamAVWin.Trojan.Vobfus-35
FireEyeGeneric.mg.29d934e2e27f80b4
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.eq
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Chinky.7
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan.VBObfus.f
VirITTrojan.Win32.SHeur4.MTF
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/AutoRun.VB.AQN
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.dgpv
BitDefenderGen:Variant.Chinky.7
NANO-AntivirusTrojan.Win32.Jorik.khcnas
AvastWin32:AutoRun-CMZ [Trj]
TencentWorm.Win32.Vobfus.hn
TACHYONWorm/W32.Vobfus.290816
SophosMal/VBCheMan-B
F-SecureTrojan.TR/Otran.ammy
DrWebTrojan.VbCrypt.81
TrendMicroWORM_VOBFUS.SM31
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Chinky.7 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Chinky.7
WebrootW32.Trojan.Diple.Gen
GoogleDetected
AviraTR/Otran.ammy
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Chinky.7
ViRobotWorm.Win32.A.WBNA.290816.BY
ZoneAlarmWorm.Win32.Vobfus.dgpv
MicrosoftWorm:Win32/Vobfus!pz
VaristW32/Vobfus.Z.gen!Eldorado
AhnLab-V3Trojan/Win32.Diple.R19483
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36744.rm0@ayCRS8ei
ALYacGen:Variant.Chinky.7
MAXmalware (ai score=86)
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM31
RisingWorm.VobfusEx!1.99DC (CLASSIC)
YandexTrojan.GenAsa!iefZtqwFMM4
IkarusVirus.Win32.Virut
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Diple.EJQE!tr
AVGWin32:AutoRun-CMZ [Trj]
Cybereasonmalicious.4a2a88
DeepInstinctMALICIOUS

How to remove Worm.Win32.Vobfus.dgpv?

Worm.Win32.Vobfus.dgpv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment