Worm

About “Worm:Win32/Vobfus.CI” infection

Malware Removal

The Worm:Win32/Vobfus.CI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.CI virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Vobfus.CI?


File Info:

name: 307F8615717448A9DE0F.mlw
path: /opt/CAPEv2/storage/binaries/229a9c6bc596db64faa7725cca24d4587f6d16cd272eae28ee618603a4b83437
crc32: 962DDE5F
md5: 307f8615717448a9de0f51dfb5b7a32f
sha1: ef02f51e6e74efeacf47df3daf5380ad0be5ea80
sha256: 229a9c6bc596db64faa7725cca24d4587f6d16cd272eae28ee618603a4b83437
sha512: a33a35b2c3d586dc9c9a654b2057055dd3def23a77ed16976ad40495a02949a32278046d54eb173d3de169e0787bd1f1b71b5d16fe93396ac745987b04f1b173
ssdeep: 3072:sob6FEjRHU4Fo9Y1P8osUpJbPfIM7t0S5:s/0RHUuomP8oxZfh2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T170C381297791E23FD529CBF42D1A83B080A96D3421E5AD13F7C64A1673F2DA79321783
sha3_384: f6440239ee5b352c437bd09288e07bf03f68210f19b704743a0ef0f269cded17812cb35b20548a49625a8ecda4057455
ep_bytes: 68f4324000e8f0ffffff000000000000
timestamp: 2011-06-18 04:36:09

Version Info:

Translation: 0x0409 0x04b0
ProductName: tlGMozYcDbFDobEufR
FileVersion: 1.00
ProductVersion: 1.00
InternalName: NPBcduoOoG
OriginalFilename: NPBcduoOoG.exe

Worm:Win32/Vobfus.CI also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lr3L
ClamAVWin.Trojan.Changeup-6169544-0
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.cm
ALYacGen:Variant.VBKrypt.55
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.VBKrypt.55
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaMalware:Win32/km_2ff15.None
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.e6e74e
BaiduWin32.Worm.Pronny.d
VirITTrojan.Win32.VBKrypt.DQHI
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.AHJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.WBNA.ipa
BitDefenderGen:Variant.VBKrypt.55
NANO-AntivirusTrojan.Win32.Chinky.covkql
SUPERAntiSpywareTrojan.Agent/Gen-FakeAlert
MicroWorld-eScanGen:Variant.VBKrypt.55
AvastWin32:VB-ABDC [Drp]
TencentWorm.Win32.WBNA.hp
EmsisoftGen:Variant.VBKrypt.55 (B)
F-SecureTrojan.TR/Chinky.6256
DrWebTrojan.VbCrypt.60
TrendMicroWORM_VOBFUS.SMHE
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.307f8615717448a9
SophosMal/VB-XV
SentinelOneStatic AI – Malicious PE
VaristW32/Vobfus.W.gen!Eldorado
AviraTR/Chinky.6256
MAXmalware (ai score=87)
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftWorm:Win32/Vobfus.CI
XcitiumTrojWare.Win32.Diple.HJ@4ln2s1
ArcabitTrojan.VBKrypt.55
ZoneAlarmWorm.Win32.WBNA.ipa
GDataWin32.Trojan.PSE.10I69CR
GoogleDetected
AhnLab-V3Trojan/Win32.VBKrypt.R18935
Acronissuspicious
McAfeeVBObfus.g
TACHYONWorm/W32.VB-WBNA.118784
VBA32BScope.Worm.WBNA
Cylanceunsafe
PandaW32/Vobfus.GEP
TrendMicro-HouseCallWORM_VOBFUS.SMHE
RisingWorm.Win32.WBNA.e (CLASSIC)
YandexTrojan.GenAsa!0/cSIMVANpI
IkarusVirus.Worm.SuspectCRC
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/WBNA.AOW!worm
BitDefenderThetaAI:Packer.B645DEE820
AVGWin32:VB-ABDC [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm:Win32/Vobfus.CI?

Worm:Win32/Vobfus.CI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment