Worm

Worm.Win32.Vobfus.dvee removal guide

Malware Removal

The Worm.Win32.Vobfus.dvee is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.dvee virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.Vobfus.dvee?


File Info:

name: 2E4DE3E14DF9EFAA8CBA.mlw
path: /opt/CAPEv2/storage/binaries/3ede6496f040bb5fc8c7a151a0f54e72c8250ddc73e8d40b135d545313615871
crc32: 219FD6AC
md5: 2e4de3e14df9efaa8cba911702ec0e77
sha1: 8b2b39980fcbdcd5bef3b197d325a1ae31754e46
sha256: 3ede6496f040bb5fc8c7a151a0f54e72c8250ddc73e8d40b135d545313615871
sha512: 1deec0570e889f6245d0a7ef5cbf6b3b808331c696e56a129a3da161cc021ca385bd131905086d62a238e4caee0a487389788ecaf9cf8cbd8c604e328bca184f
ssdeep: 6144:4Rl7FNnnxSbuxN8b7giqR20NGNccko5Knvmb7/D26i02maSTOarRUa:Ql7FNnEuxN8cGNccko5Knvmb7/D26i0H
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13E44A223AA21E01FE64589F02D5E97A67C795D3B2A90AC1373C07F1D257069BB4B234F
sha3_384: 64d21ead2b3eda10557e3f2630e7ef1376f4fe0a837d12951fe0c67dbc7ed1f884f8a0fdb7546903ddeae3b803b322f2
ep_bytes: 6878394000e8eeffffff000000000000
timestamp: 2011-11-09 18:58:27

Version Info:

ProductName:
FileVersion: 1.00
ProductVersion: 1.00
InternalName:
OriginalFilename:

Worm.Win32.Vobfus.dvee also known as:

BkavW32.AIDetectMalware
AVGWin32:Agent-BAVG [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.950
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.cm
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Barys.950
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.14df9e
BaiduWin32.Worm.Autorun.l
VirITWorm.Win32.Generic.BCKQ
SymantecW32.Changeup!gen15
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.APA
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.dvee
BitDefenderGen:Variant.Barys.950
NANO-AntivirusTrojan.Win32.WBNA.csnmmv
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:Agent-BAVG [Trj]
TencentWorm.Win32.Vobfus.n
EmsisoftGen:Variant.Barys.950 (B)
F-SecureTrojan.TR/Zusy.32754
DrWebTrojan.VbCrypt.77
TrendMicroWORM_VOBFUS.SMAB
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.2e4de3e14df9efaa
SophosMal/SillyFDC-T
SentinelOneStatic AI – Malicious PE
VaristW32/Vobfus.Z.gen!Eldorado
AviraTR/Zusy.32754
MAXmalware (ai score=80)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Barys.950
ViRobotTrojan.Win32.A.Diple.258048.G
ZoneAlarmWorm.Win32.Vobfus.dvee
GDataGen:Variant.Barys.950
GoogleDetected
AhnLab-V3Trojan/Win32.Diple.R16325
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36802.pm0@aiDqdWbi
ALYacGen:Variant.Barys.950
TACHYONWorm/W32.Vobfus.258048.C
VBA32BScope.Trojan-Dropper.VB.01545
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMAB
RisingWorm.VobfusEx!1.99DC (CLASSIC)
YandexTrojan.GenAsa!DMq4PknFD/I
IkarusTrojan.Win32.Otran
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Diple.EJQE!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan:Win/Vobfus.465344fc

How to remove Worm.Win32.Vobfus.dvee?

Worm.Win32.Vobfus.dvee removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment