Worm

Should I remove “Worm:Win32/Vobfus.B”?

Malware Removal

The Worm:Win32/Vobfus.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.B virus can do?

  • Authenticode signature is invalid

How to determine Worm:Win32/Vobfus.B?


File Info:

name: F5DF3F42B44F5F6E4BBE.mlw
path: /opt/CAPEv2/storage/binaries/0e2b068521f1f9b1749a937cc8858714db01b066c2a3aa63a04a347b4ab45f16
crc32: CBDAB099
md5: f5df3f42b44f5f6e4bbef8a7328c3479
sha1: 22462d16e613314c96e4b80e9431e677ddb67ec3
sha256: 0e2b068521f1f9b1749a937cc8858714db01b066c2a3aa63a04a347b4ab45f16
sha512: c1780ac7345c2f1e084dfbb4c28e5acc88e4dbad1c283a392b2bd05527578a3d88971458a5d5618919bc7c0f284f6f0d35cdb504e40a37c248316243cd45c8b7
ssdeep: 768:7IzsIdmoIBW+V1DBYBpiANtg9bPHhHXPNWNCB+Gc1H8zHvc:7UsIdmoIBW+7DCrtg9zxB+52Dvc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T173E2D6277731082BDA8DB239775386DB21E7A0890F8F4B077521637CBC26E901966B97
sha3_384: 7b6c652c2c7754eb8dbbd258be5db5c965a72faf83170029dc2ea0c12ea700e60c521fefcaac08f0af0c839cc414aeff
ep_bytes: 6810124000e8eeffffff000000000000
timestamp: 2000-01-01 12:00:00

Version Info:

Translation: 0x0409 0x04b0

Worm:Win32/Vobfus.B also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Chinky.2
CAT-QuickHealTrojan.VBCrypt.MF.139
SkyhighBehavesLike.Win32.VBObfus.nm
McAfeeVBObfus
Cylanceunsafe
ZillyaWorm.VBNA.Win32.62556
SangforSuspicious.Win32.Save.vb
K7AntiVirusNetWorm ( 700000151 )
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.2b44f5
BaiduWin32.Worm.VB.li
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.FL
APEXMalicious
TrendMicro-HouseCallWORM_VB.SMP
ClamAVWin.Trojan.Agent-35777
KasperskyWorm.Win32.VBNA.abqp
BitDefenderGen:Trojan.Chinky.2
NANO-AntivirusTrojan.Win32.VB.coonke
SUPERAntiSpywareTrojan.Agent/Gen-NameThief[Smart]
AvastWin32:AutoRun-AYS [Wrm]
EmsisoftGen:Trojan.Chinky.2 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner.7170
VIPREGen:Trojan.Chinky.2
TrendMicroWORM_VB.SMP
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.f5df3f42b44f5f6e
SophosMal/SillyFDC-D
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=83)
JiangminWorm/VBNA.hbui
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/VB.W.gen!Eldorado
Antiy-AVLTrojan/Win32.VB
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus.B
XcitiumWorm.Win32.VBNA.~L@1ealkg
ArcabitTrojan.Chinky.2
ZoneAlarmWorm.Win32.VBNA.abqp
GDataGen:Trojan.Chinky.2
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Basun.R1388
Acronissuspicious
VBA32SScope.Trojan.VB.Svchorse.030
ALYacGen:Trojan.Chinky.2
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.gen.worm
RisingWorm.Win32.Vobfus.l (CLASSIC)
YandexTrojan.GenAsa!qdIQH/S6Vuw
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBNA.E!tr
BitDefenderThetaAI:Packer.41CA06831F
AVGWin32:AutoRun-AYS [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudWorm:Win/Vobfus.4e6d53db

How to remove Worm:Win32/Vobfus.B?

Worm:Win32/Vobfus.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment