Worm

Worm.Win32.Vobfus.exhx information

Malware Removal

The Worm.Win32.Vobfus.exhx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.exhx virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.Vobfus.exhx?


File Info:

name: 8DE1175E4C5BFC40C728.mlw
path: /opt/CAPEv2/storage/binaries/cda643fb4b00198e77874e57911c826b3d85a9b234765d2cfe6386151d221e2e
crc32: F6C9BCA9
md5: 8de1175e4c5bfc40c728a764c2feb11a
sha1: a52264fe1b7ee6a9fe59638d922a449c32a44905
sha256: cda643fb4b00198e77874e57911c826b3d85a9b234765d2cfe6386151d221e2e
sha512: c11e5b3814791f4cd3d776090cb63c031b2c2476cc815849d6e94606f1547a7eb79acfdabc9ab046a7527db5f0cfee9c772b2f63f267ed2a62861520d90e6235
ssdeep: 3072:JrApLDuLE2goAIl2EwrLSm5WLyD1v6jVAfunNg4K7QmcY+MZGQ:SpLDuLE2gRGoXr5Gyhv6jVAfKglLZG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10AC31D5F7B08959EF48A49B964266B5B7D592E340244B887E7838B4C70F16CBF8F070B
sha3_384: 864295fcd7cefb0134a1db9c0b9f5225de4d9904d9fa3fcd5ab3e4f50aea0d32d8f80cbb61d82d4b7abee2d654816acd
ep_bytes: 6850224000e8eeffffff000000000000
timestamp: 2009-06-09 17:48:35

Version Info:

Translation: 0x0409 0x04b0

Worm.Win32.Vobfus.exhx also known as:

BkavW32.PhomeacEkalmN.Trojan
LionicWorm.Win32.Vobfus.o!c
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner.64538
MicroWorld-eScanTrojan.Agent.VB.BEF
FireEyeGeneric.mg.8de1175e4c5bfc40
CAT-QuickHealWorm.VobfusVMF.S20620163
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeDownloader-CJX.gen.u
Cylanceunsafe
ZillyaWorm.Vobfus.Win32.1519707
SangforSuspicious.Win32.Save.vb
AlibabaWorm:Win32/Vobfus.1bbbdf77
K7GWEmailWorm ( 000d1b661 )
K7AntiVirusEmailWorm ( 000d1b661 )
BitDefenderThetaAI:Packer.517241B11F
VirITTrojan.Win32.VB.IQE
Paloaltogeneric.ml
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.EW
APEXMalicious
TrendMicro-HouseCallWORM_AUTORUN.CFC
AvastWin32:AutoRun-AXP [Trj]
ClamAVWin.Trojan.VB-1074
KasperskyWorm.Win32.Vobfus.exhx
BitDefenderTrojan.Agent.VB.BEF
NANO-AntivirusTrojan.Win32.Vobfus.fiwihy
SUPERAntiSpywareTrojan.Agent/Gen-NameThief[Smart]
TencentWorm.Win32.Vobfus.haq
EmsisoftTrojan.Agent.VB.BEF (B)
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Worm.Autorun.l
VIPRETrojan.Agent.VB.BEF
TrendMicroWORM_AUTORUN.CFC
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-D
IkarusVirus.Win32.AutoRun
MAXmalware (ai score=100)
JiangminWorm.Vobfus.qyzh
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/AutoRun.L.gen!Eldorado
Antiy-AVLWorm/Win32.AutoRun
KingsoftWin32.Worm.Vobfus.exhx
MicrosoftWorm:Win32/Autorun.UE
XcitiumWorm.Win32.Autorun.~d5@1n9pnj
ArcabitTrojan.Agent.VB.BEF
ViRobotWorm.Win32.Autorun.128000.BF
ZoneAlarmWorm.Win32.Vobfus.exhx
GDataTrojan.Agent.VB.BEF
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Basun.R1388
Acronissuspicious
ALYacTrojan.Agent.VB.BEF
VBA32OScope.Trojan.VB.01580
MalwarebytesGeneric.Malware.AI.DDS
PandaGeneric Malware
ZonerTrojan.Win32.5125
RisingTrojan.Win32.VBCode.aig (CLASSIC)
YandexTrojan.GenAsa!vgzaXTv/ojM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.9683075.susgen
FortinetW32/VB.UYT!worm
AVGWin32:AutoRun-AXP [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:Win/Autorun.09cedc02

How to remove Worm.Win32.Vobfus.exhx?

Worm.Win32.Vobfus.exhx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment