Worm

Worm:Win32/Vobfus.AN removal instruction

Malware Removal

The Worm:Win32/Vobfus.AN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.AN virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Vobfus.AN?


File Info:

name: 06602B6892CE5647BC28.mlw
path: /opt/CAPEv2/storage/binaries/d05b997150825fbf1a5943938e412f6afb6d91c91b121d5e0df778a7e56cd71d
crc32: 52936FF8
md5: 06602b6892ce5647bc281f202b791102
sha1: c703f489945fda5f67faf7531017f9780a78e98d
sha256: d05b997150825fbf1a5943938e412f6afb6d91c91b121d5e0df778a7e56cd71d
sha512: 6ee744ecc4fb601ef3cecba4857a81fb4ee19869e2e8ae9b30fbcb37de4ef7974584d69d773a7aa38dfcc0635fc485738f82aada877b9db213d674304290329d
ssdeep: 768:qsOhMjRBZdr+KGz5BAtpm4eutfrWTVtTZ/BliKG1jiTa9McTfkQ3sbX:qSJdS6pm4aTZ5XG1jiTa9McrkQ8bX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18693422F73413598E51515F53A8EC2D7A2E6A4FC8A1751C2CB753958A82CF3B2C08DAF
sha3_384: 668c068d1c183c4182e9a1b6ae6e96b845e32f7a9653d02fe080d5997f2cd471335beba497ae998ff0f40176937b5e7b
ep_bytes: 6878114000e8f0ffffff000000000000
timestamp: 2010-11-24 13:55:18

Version Info:

Translation: 0x0409 0x04b0
ProductName: QrZfNO
FileVersion: 7.50
ProductVersion: 7.50
InternalName: QrZfN
OriginalFilename: QrZfN.exe

Worm:Win32/Vobfus.AN also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.VBNA.li7E
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Jaik.11356
CAT-QuickHealWorm.WbnaMF.S18680782
SkyhighBehavesLike.Win32.VBObfus.nt
McAfeeDownloader-CJX.gen.l
MalwarebytesGeneric.Worm.AutoRun.DDS
VIPREGen:Variant.Jaik.11356
SangforSuspicious.Win32.Save.vb
AlibabaWorm:Win32/vobfus.1030
K7GWTrojan ( 001f4fd41 )
K7AntiVirusTrojan ( 001f4fd41 )
BaiduWin32.Worm.VB.al
VirITTrojan.Win32.Generic.BZMB
SymantecW32.Changeup!gen9
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.XH
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMIB
Paloaltogeneric.ml
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.WBNA.ipa
BitDefenderGen:Variant.Jaik.11356
NANO-AntivirusTrojan.Win32.VB.cmxqte
SUPERAntiSpywareTrojan.Agent/Gen-Vban
AvastWin32:AutoRun-BRC [Trj]
TencentWorm.Win32.Wbna.ff
EmsisoftGen:Variant.Jaik.11356 (B)
F-SecureTrojan.TR/Otran.AA
DrWebWin32.HLLW.Autoruner.36338
TrendMicroWORM_VOBFUS.SMIB
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.06602b6892ce5647
SophosMal/SillyFDC-D
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=86)
JiangminWorm/VBNA.gxpr
GoogleDetected
AviraTR/Otran.AA
VaristW32/Vobfus.L.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftWorm:Win32/Vobfus.AN
XcitiumWorm.Win32.VB.ww@2ajsup
ArcabitTrojan.Jaik.D2C5C
ViRobotWorm.Win32.Agent.94208
ZoneAlarmWorm.Win32.WBNA.ipa
GDataGen:Variant.Jaik.11356
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.VBNA.R19315
BitDefenderThetaAI:Packer.8C6F3BAB20
ALYacGen:Variant.Jaik.11356
TACHYONWorm/W32.VB-VBNA.94208.B
VBA32SScope.Trojan.VBRA.5166
Cylanceunsafe
PandaGeneric Malware
RisingWorm.Autorun!1.99EA (CLASSIC)
YandexTrojan.GenAsa!DJXzsFP6hFw
IkarusTrojan.Win32.Otran
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/AutoRun.XM!worm
AVGWin32:AutoRun-BRC [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Vobfus.8b5d2c83

How to remove Worm:Win32/Vobfus.AN?

Worm:Win32/Vobfus.AN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment