Worm

Worm:Win32/Vobfus.C information

Malware Removal

The Worm:Win32/Vobfus.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.C virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the system manufacturer, likely for anti-virtualization
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

ns1.theimageparlour.net

How to determine Worm:Win32/Vobfus.C?


File Info:

crc32: 037B85C2
md5: a066223448fb3dc7434c014931f646b1
name: A066223448FB3DC7434C014931F646B1.mlw
sha1: cbaa9a6d0a40bcacf92df1428c98f626c2bf4705
sha256: 87f168fe4ebe1f626c9e9e90cc60949a02a56bddb13001ac3c233b69699def52
sha512: f6042d65fa3f4df9aaf18df7a066f0a824527c805667132d456bcf47ba77e854355b7f7ce53a204350465fac9b343237339920ecc4bb8066cedd06a0b3895a12
ssdeep: 768:c4NEhmegxyK30obv+6wH9H7MfygXaDMFQXD7e:c4amvyKEo36NNDsQXD7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Worm:Win32/Vobfus.C also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.70291
FireEyeGeneric.mg.a066223448fb3dc7
CAT-QuickHealTrojan.Vobfus.gen
McAfeeVBObfus
CylanceUnsafe
ZillyaWorm.VBNA.Win32.37042
SangforMalware
K7AntiVirusEmailWorm ( 00568eae1 )
BitDefenderTrojan.GenericKDZ.70291
K7GWEmailWorm ( 00568eae1 )
Cybereasonmalicious.448fb3
InvinceaML/PE-A + W32/SillyFDC-FU
BaiduWin32.Worm.AutoRun.cj
CyrenW32/Vobfus.A
SymantecW32.SillyFDC
TotalDefenseWin32/Vobfus.A
APEXMalicious
AvastWin32:VB-NIK [Wrm]
ClamAVWin.Trojan.Agent-35776
KasperskyWorm.Win32.VBNA.isu
NANO-AntivirusTrojan.Win32.VB.efhxyv
ViRobotWorm.Win32.VBNA.49152.ACZ
RisingTrojan.Win32.VBCode.ald (CLASSIC)
Ad-AwareTrojan.GenericKDZ.70291
SophosW32/SillyFDC-FU
ComodoWorm.Win32.VBNA.~gen@1qlvkj
F-SecureWorm.WORM/VBNA.isu
DrWebTrojan.Siggen.4099
VIPRETrojan.Win32.Vobfus.C (v)
TrendMicroWORM_ESFURY.SMA
McAfee-GW-EditionBehavesLike.Win32.VBObfus.pt
EmsisoftTrojan.GenericKDZ.70291 (B)
SentinelOneStatic AI – Malicious PE
JiangminWorm/VBNA.hchp
eGambitUnsafe.AI_Score_100%
AviraWORM/VBNA.isu
MAXmalware (ai score=88)
Antiy-AVLWorm/Win32.VBNA.a
KingsoftWin32.Troj.AutoRunVBT.xa.49152
MicrosoftWorm:Win32/Vobfus.C
ArcabitTrojan.Generic.D11293
SUPERAntiSpywareTrojan.Agent/Gen-FakeAlert
ZoneAlarmWorm.Win32.VBNA.isu
GDataTrojan.GenericKDZ.70291
CynetMalicious (score: 100)
AhnLab-V3Win32/Vbna3.worm.Gen
Acronissuspicious
BitDefenderThetaAI:Packer.2A082D391F
ALYacTrojan.GenericKDZ.70291
TACHYONTrojan/W32.VB-Obfuscated.49152
VBA32SScope.Trojan.VB.Svchorse.024
MalwarebytesWorm.VBAgent
PandaW32/Vobfus.gen.worm
ESET-NOD32Win32/AutoRun.VB.GA
TrendMicro-HouseCallWORM_ESFURY.SMA
TencentWorm.Win32.VBna.a
YandexTrojan.GenAsa!/pNLMyTT40M
IkarusVirus.Worm.Win32.VBNA
MaxSecureWorm.W32.VBNA.isu
FortinetW32/VBNA.D!tr
AVGWin32:VB-NIK [Wrm]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Trojan.Win32.Chinky.B

How to remove Worm:Win32/Vobfus.C?

Worm:Win32/Vobfus.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment