Worm

Should I remove “Worm.Win32.Vobfus.ykp”?

Malware Removal

The Worm.Win32.Vobfus.ykp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.ykp virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm.Win32.Vobfus.ykp?


File Info:

name: AFCD095158289C881E99.mlw
path: /opt/CAPEv2/storage/binaries/f90969a6bc02a47d47e7b3290b84ae27adc3b42cb871fe8a760554f9e2be56d2
crc32: 8673BA33
md5: afcd095158289c881e99cea91bd31c74
sha1: 0319fb3f95157f271faa577f75b59d3acc07b47d
sha256: f90969a6bc02a47d47e7b3290b84ae27adc3b42cb871fe8a760554f9e2be56d2
sha512: fc58b77abc7cb2d25515fca96946ea69d652e7d66b9a89ccd7fb63c1a4765abe580a5a2055ce982e7f30b993a7dd88600f0396229a7bd72c8c0b5d7357c147c8
ssdeep: 6144:Gte2BsHkq8xJYd1BeJuESHr4YWzOMlql49e1/lcduanJntih/FlVjf5PfbZjo/Ji:/2BsHkq8xJYdlEC4YWzZvRMUqD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11F840A2B67A0F96AE525CBF0296C43748569B83114E5AD1BEAC01F1973F6E87C237313
sha3_384: 56428892d15d33e750d8d7948b49532109e58d5ac134f8595dcf7ebea2fea26b34387baf7dba3bf3162ad819c2b63425
ep_bytes: 6878484000e8f0ffffff000000000000
timestamp: 2012-10-13 03:46:47

Version Info:

Translation: 0x0409 0x04b0
ProductName: twinemaking
FileVersion: 5.74
ProductVersion: 5.74
InternalName: nonusurping
OriginalFilename: nonusurping.exe

Worm.Win32.Vobfus.ykp also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.14907
FireEyeGeneric.mg.afcd095158289c88
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.fm
ALYacGen:Variant.Symmi.14907
MalwarebytesVBObfus.Worm.Spreader.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
BaiduWin32.Worm.Pronny.d
VirITTrojan.Win32.VB.CODN
SymantecW32.Changeup
ESET-NOD32a variant of Win32/VBObfus.CZ
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMQ4
AvastWin32:VB-AIYR [Trj]
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.ykp
BitDefenderGen:Variant.Symmi.14907
NANO-AntivirusTrojan.Win32.Autoruner1.hcpaej
TencentWorm.Win32.Vobfus.kat
EmsisoftGen:Variant.Symmi.14907 (B)
F-SecureTrojan.TR/Symmi.3566984
DrWebWin32.HLLW.Autoruner1.28016
VIPREGen:Variant.Symmi.14907
TrendMicroWORM_VOBFUS.SMQ4
SophosTroj/VB-HCM
IkarusWorm.Win32.Vobfus
JiangminWorm/WBNA.dfbt
Webroot
GoogleDetected
AviraTR/Symmi.3566984
VaristW32/VB.HE.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.999
XcitiumTrojWare.Win32.Pronny.EE@4qvpy8
ArcabitTrojan.Symmi.D3A3B
ViRobotWorm.Win32.A.Vobfus.376832
ZoneAlarmWorm.Win32.Vobfus.ykp
GDataGen:Variant.Symmi.14907
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Vobfus.R42639
BitDefenderThetaGen:NN.ZevbaF.36804.xm1@ayjTrLoi
TACHYONWorm/W32.Vobfus.376888
VBA32BScope.Trojan.Diple
Cylanceunsafe
PandaTrj/Genetic.gen
RisingMalware.FakeFolder/ICON!1.6AC4 (CLASSIC)
YandexTrojan.GenAsa!9333E1wWfDI
MAXmalware (ai score=81)
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-AIYR [Trj]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.d303268f

How to remove Worm.Win32.Vobfus.ykp?

Worm.Win32.Vobfus.ykp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment