Worm

Worm.Win32.Vobfus.dgpv removal guide

Malware Removal

The Worm.Win32.Vobfus.dgpv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.dgpv virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.Vobfus.dgpv?


File Info:

name: 6587950BDE641CDE6D81.mlw
path: /opt/CAPEv2/storage/binaries/375f82d18695b1e3e5b9c203f93d7f86dbc5b2535a98c00d15891e1091a6135c
crc32: 741AE43A
md5: 6587950bde641cde6d816d20e5321b32
sha1: 1c629f61c1d6741de058b5af782e7f6151341b88
sha256: 375f82d18695b1e3e5b9c203f93d7f86dbc5b2535a98c00d15891e1091a6135c
sha512: ddfed77ae1d2da1462f67ef52927f4b3bd4ee93c09884046dc1aba169c6adea5691fed701ea1fa78b23a5611299a4e35f3f7423deb162e0f02659fe1bee73d61
ssdeep: 3072:o0A2afa16bn4DpS41Zr8EbjfmNwXl1RgxfGDP8F2dqMOkeuF7SzotBXOs:zay16z4Dp7R8cA0l1RpLtJj7SkbN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E45484157390F72DD520C5F02A4A83A0A87EDD3264E56803FAC13F6A77B1DABE161727
sha3_384: f246d2c4e52d5c18bbfa06225e8c6f40e748f4dda9e2838c06df7874c2f8f96e78adbde15286d5900bb5a3e30d84c9b8
ep_bytes: 68e44a4000e8eeffffff000000000000
timestamp: 2012-01-07 18:24:49

Version Info:

0: [No Data]

Worm.Win32.Vobfus.dgpv also known as:

BkavW32.AIDetectMalware
AVGWin32:AutoRun-CMZ [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.431193
FireEyeGeneric.mg.6587950bde641cde
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.eq
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Barys.431193
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
BaiduWin32.Trojan.VBObfus.f
VirITTrojan.Win32.SHeur4.MTF
SymantecW32.Changeup
ESET-NOD32a variant of Win32/AutoRun.VB.AQN
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:AutoRun-CMZ [Trj]
ClamAVWin.Trojan.Vobfus-35
KasperskyWorm.Win32.Vobfus.dgpv
BitDefenderGen:Variant.Barys.431193
NANO-AntivirusTrojan.Win32.Jorik.khcnas
TencentWorm.Win32.Vobfus.hn
EmsisoftGen:Variant.Barys.431193 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebTrojan.VbCrypt.150
TrendMicroWORM_VOBFUS.SMAB
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-U
IkarusSality.Win32
VaristW32/Vobfus.AI.gen!Eldorado
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=89)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumWorm.Win32.VB.AUB@4ol77w
ArcabitTrojan.Barys.D69459
ViRobotWorm.Win32.A.WBNA.290816.BY
ZoneAlarmWorm.Win32.Vobfus.dgpv
GDataGen:Variant.Barys.431193
GoogleDetected
AhnLab-V3Trojan/Win.Jorik.R490516
Acronissuspicious
BitDefenderThetaAI:Packer.8DE7EE741E
ALYacGen:Variant.Barys.431193
TACHYONTrojan/W32.VB-Agent.299008.BU
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMAB
RisingWorm.Pronoy!1.9A2F (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Diple.EJQE!tr
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Fake.AZ

How to remove Worm.Win32.Vobfus.dgpv?

Worm.Win32.Vobfus.dgpv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment