Worm

What is “Worm.Win32.Vobfus.dhos”?

Malware Removal

The Worm.Win32.Vobfus.dhos is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.dhos virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

ns1.player1253.com
ns1.videoall.net
ns1.mediashares.org

How to determine Worm.Win32.Vobfus.dhos?


File Info:

crc32: 3D5B7F3F
md5: b944d90da74b819efedf789cedb9c848
name: B944D90DA74B819EFEDF789CEDB9C848.mlw
sha1: 798a16bbe0100542642e32b942aeb863c0da1027
sha256: 7d7361f1675479ff9088ad2039d918c1ea44e54c53ad1b19ed312502e7b10bed
sha512: 01053ddfe94bd216e37380f18b98e3c7a007c2aae3d67dbe7ea72f9bbf99facaa5a3fbb24614c953ae2717017e866e133fcda4062184bdbc75cf3788863e04dd
ssdeep: 3072:Zl04lgYg9bVtgfzFHfzb51QRPr8GDi1B:ZlFg59joFJyr8Gu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: XKlje6904
FileVersion: 4.61
CompanyName: XKlje6904
ProductName: XKlje82
ProductVersion: 4.61
OriginalFilename: XKlje6904.exe

Worm.Win32.Vobfus.dhos also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.VBKrypt.23
FireEyeGeneric.mg.b944d90da74b819e
Qihoo-360HEUR/QVM03.0.08BC.Malware.Gen
McAfeeDownloader-CJX.gen.o
MalwarebytesGeneric.Trojan.Malicious.DDS
SUPERAntiSpywareTrojan.Agent/Gen-Trafog
K7AntiVirusTrojan-Downloader ( 001ff72a1 )
K7GWTrojan-Downloader ( 001ff72a1 )
Cybereasonmalicious.da74b8
BaiduWin32.Worm.AutoRun.cj
CyrenW32/VB.BR.gen!Eldorado
SymantecW32.Changeup!gen10
TotalDefenseWin32/Vobfus.I!generic
APEXMalicious
AvastWin32:VB-QRI [Drp]
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.dhos
BitDefenderGen:Variant.VBKrypt.23
NANO-AntivirusTrojan.Win32.Autoruner.coonjn
ViRobotTrojan.Win32.A.VBKrypt.258048.CN
Ad-AwareGen:Variant.VBKrypt.23
EmsisoftGen:Variant.VBKrypt.23 (B)
ComodoWorm.Win32.VB.YK@4on2wz
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner.42131
VIPRETrojan.Win32.Vobfus.a (v)
TrendMicroWORM_VBNA.SMTB
McAfee-GW-EditionBehavesLike.Win32.Downloader.dm
SophosML/PE-A + Mal/SillyFDC-I
SentinelOneStatic AI – Malicious PE – Worm
GDataGen:Variant.VBKrypt.23
JiangminTrojan/Generic.arygj
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
ArcabitTrojan.VBKrypt.23
ZoneAlarmWorm.Win32.Vobfus.dhos
MicrosoftWorm:Win32/Vobfus.gen!E
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VBKrypt.R2546
Acronissuspicious
BitDefenderThetaAI:Packer.34FBDFFB20
ALYacGen:Variant.VBKrypt.23
TACHYONTrojan/W32.VB-Krypt.258048
VBA32Trojan.VBRA.07070
ESET-NOD32Win32/AutoRun.VB.YK
TrendMicro-HouseCallWORM_VBNA.SMTB
RisingWorm.Agent!1.D163 (CLASSIC)
YandexTrojan.GenAsa!kzGc1bM1Y3c
MAXmalware (ai score=88)
FortinetW32/AutoRun.XM!worm
AVGWin32:VB-QRI [Drp]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm.Win32.Vobfus.dhos?

Worm.Win32.Vobfus.dhos removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment