Worm

Worm:Win32/Vobfus.AP!MTB malicious file

Malware Removal

The Worm:Win32/Vobfus.AP!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.AP!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm:Win32/Vobfus.AP!MTB?


File Info:

name: 0B27808BD45031ADCD35.mlw
path: /opt/CAPEv2/storage/binaries/a3f1f2791964753536448abc14732d1ac6f7a6c6239b748af68bb0c9b890d901
crc32: 74ABCBC3
md5: 0b27808bd45031adcd351afad1849adc
sha1: 079dbeca0bb7479fecaa90f1d571bbba85c19109
sha256: a3f1f2791964753536448abc14732d1ac6f7a6c6239b748af68bb0c9b890d901
sha512: a8884a4f6b6a6f39655ab2a62c7d4bc13113c7cf7e01d60f1fcdf122c0cc7cb13ef53cc503b65680d8054c0bdc3c4282850af380fc6702720d9a54eb126fc555
ssdeep: 3072:6j/2wWOtehcy1imsW7A0g3XDYHYTvZm3ov5Q4/cMIVH5bEvhSSqeLSqnjYH:0efTyy1imdJgc4s2QRhH5IXS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AC348525A3D0FB3DE860C6F82944469058AAEE3768D2AC17F6D15B1677B1E47F220373
sha3_384: 4c507ef9891fc2a684791e4f95cbc54086bab053a1e1d380e85ebc6195bc9bc99e80b3d136c64fe79b93e92a046ac3a3
ep_bytes: 68cc4e4000e8eeffffff000000000000
timestamp: 2012-06-07 20:29:58

Version Info:

0: [No Data]

Worm:Win32/Vobfus.AP!MTB also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lyW5
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.95984
ClamAVWin.Trojan.Changeup-6169544-0
CAT-QuickHealTrojan.Beebone.D
McAfeeVBObfus.da
MalwarebytesMalware.AI.2085658731
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Vobfus.a2959777
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.bd4503
BaiduWin32.Trojan.VBObfus.f
VirITTrojan.Win32.SHeur4.AHKR
CyrenW32/Vobfus.AD.gen!Eldorado
SymantecW32.Changeup
ESET-NOD32Win32/Pronny.AZ
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.erzq
BitDefenderTrojan.GenericKDZ.95984
NANO-AntivirusTrojan.Win32.Diple.cmtitq
AvastWin32:Agent-AZYN [Trj]
TencentWorm.Win32.Vobfus.n
EmsisoftTrojan.GenericKDZ.95984 (B)
F-SecureTrojan.TR/Kazy.JH.75176
DrWebTrojan.VbCrypt.60
VIPRETrojan.GenericKDZ.95984
TrendMicroWORM_VOBFUS.SMJY
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dm
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.0b27808bd45031ad
SophosMal/VBCheMan-J
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.95984
JiangminTrojan/Vbobf.b
AviraTR/Kazy.JH.75176
MAXmalware (ai score=84)
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Generic.D176F0
ViRobotTrojan.Win32.A.Diple.249856.L
ZoneAlarmWorm.Win32.Vobfus.erzq
MicrosoftWorm:Win32/Vobfus.AP!MTB
GoogleDetected
AhnLab-V3Worm/Win.WBNA.R570470
BitDefenderThetaGen:NN.ZevbaF.36196.pmW@aGpwZjai
ALYacTrojan.GenericKDZ.95984
TACHYONWorm/W32.Vobfus.249856.C
VBA32BScope.Trojan.Diple
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMJY
RisingTrojan.VB!1.99F7 (CLASSIC)
YandexTrojan.GenAsa!HAD4hoZ4OnY
IkarusWorm.Win32.WBNA
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:Agent-AZYN [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Vobfus.AP!MTB?

Worm:Win32/Vobfus.AP!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment