Worm

Should I remove “Worm:Win32/Vobfus.CT”?

Malware Removal

The Worm:Win32/Vobfus.CT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.CT virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Vobfus.CT?


File Info:

name: 04066A3837E1AEB4589E.mlw
path: /opt/CAPEv2/storage/binaries/cf8fe9ad52f0560ae26c2fc12b6c9fb6d4eef05afa30b50a9406f57ea0e1e687
crc32: C6279BD5
md5: 04066a3837e1aeb4589ec6a78ca91248
sha1: 23e9909d7d6422626715ebfda79286599e90feac
sha256: cf8fe9ad52f0560ae26c2fc12b6c9fb6d4eef05afa30b50a9406f57ea0e1e687
sha512: 1414d9d752d58092e61bcd3946f70d247fd19ad6acf5d1ab7aec29e883442f4da550702965a0c4ef3bf3b5710194e1d12da8e6c57a34ef9f4b53fe761ae55296
ssdeep: 1536:tGGojZ+UUFX5EmoiHl7gRNq27ddDhJmRjfFp6jhQh8bA0zb69ZeqpZj2jMhuyse7:tG5QUmvFKnAjfFQLA0zbPq36jRNE/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B8C3A22673C0F63EC516C7F82D1A83A0806EAD7521966D03F7C65B1AB6F1E939325B43
sha3_384: 66750704236f2f652ecca9e0648b109318ab988818097da05aa8710ed193bd88faf29b5da5fa8230da9f3fc2f5f943ef
ep_bytes: 68f8304000e8f0ffffff000000000000
timestamp: 2011-07-06 04:01:18

Version Info:

Translation: 0x0409 0x04b0
ProductName: uiHHrNZtDETEDIP
FileVersion: 1.00
ProductVersion: 1.00
InternalName: JoeyXRhtjmzulSvb
OriginalFilename: JoeyXRhtjmzulSvb.exe

Worm:Win32/Vobfus.CT also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.79514
ClamAVWin.Trojan.VB-1758
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeVBObfus.g
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.VbCryptGen.Win32.1
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.d7d642
BitDefenderThetaAI:Packer.638E724F20
VirITWorm.Win32.Generic.AUTS
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/AutoRun.VB.AHJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.WBNA.ipa
BitDefenderGen:Variant.Symmi.79514
NANO-AntivirusTrojan.Win32.VBKrypt.cmxrud
AvastWin32:VB-ABDC [Drp]
TencentWorm.Win32.Wbna.zb
TACHYONTrojan/W32.VB-VBKrypt.122880.BW
EmsisoftGen:Variant.Symmi.79514 (B)
BaiduWin32.Worm.Pronny.d
F-SecureTrojan.TR/Dropper.VB.Gen
DrWebWin32.HLLW.Autoruner3.5744
VIPREGen:Variant.Symmi.79514
TrendMicroWORM_VBNA.SMVI
FireEyeGeneric.mg.04066a3837e1aeb4
SophosMal/SillyFDC-T
IkarusGen.Variant.VBKrypt
GDataGen:Variant.Symmi.79514
GoogleDetected
AviraTR/Dropper.VB.Gen
Antiy-AVLWorm/Win32.WBNA.gen
ArcabitTrojan.Symmi.D1369A
ZoneAlarmWorm.Win32.WBNA.ipa
MicrosoftWorm:Win32/Vobfus.CT
VaristW32/VBKrypt.BGS.gen!Eldorado
AhnLab-V3Trojan/Win32.VBKrypt.R77773
Acronissuspicious
VBA32BScope.Trojan-Dropper.VB.01545
ALYacGen:Variant.Symmi.79514
MAXmalware (ai score=89)
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallWORM_VBNA.SMVI
RisingWorm.Pronny!1.B1A8 (CLASSIC)
YandexTrojan.GenAsa!gkkM1PDzkT0
SentinelOneStatic AI – Malicious PE
FortinetW32/VBObfus.G!tr
AVGWin32:VB-ABDC [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Vobfus.CT?

Worm:Win32/Vobfus.CT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment