Worm

Worm:Win32/Vobfus.CT removal tips

Malware Removal

The Worm:Win32/Vobfus.CT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.CT virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm:Win32/Vobfus.CT?


File Info:

name: 0F3DE15B9FD43A77E0DB.mlw
path: /opt/CAPEv2/storage/binaries/01be98976859dd53eae4553d097954cafa5ba345882a0fe0723cf862d18fd1b0
crc32: 41537C98
md5: 0f3de15b9fd43a77e0db4cee46923a6e
sha1: ee1fb2bdc6e72ae147edbb68a2258a5b6fe9b43d
sha256: 01be98976859dd53eae4553d097954cafa5ba345882a0fe0723cf862d18fd1b0
sha512: 771946b825ecae09c25a8665800757bac1d08e77a73a190824716ccfefb0fc6be9b93685216ae856f8f01c578ec813cfc8b7e57c9abf92587d095ce49c024379
ssdeep: 1536:tGGolZGUtcMLEmoiHl7gRNq27ddDhJmRjfFp6jhQh8bA0zb69ZeqpZj2jMhuyse7:tGbWmvFKnAjfFQLA0zbPq36jRNEv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E5C3A22573C1F63EC516C7F82D1A83A0806EAD7421966D03F7C65B1AB6F1EA39325B43
sha3_384: 7523d60edbe9842e26eab7bb17934d5430dc9c9313c1c673d296f6c2ccaabd930ebd78887d98dcf1aa3eb860cb3844d5
ep_bytes: 68f8304000e8f0ffffff000000000000
timestamp: 2011-07-06 04:01:18

Version Info:

Translation: 0x0409 0x04b0
ProductName: uWSmJWtqkviECvQ
FileVersion: 1.00
ProductVersion: 1.00
InternalName: fcZiwwihsjZQzItT
OriginalFilename: fcZiwwihsjZQzItT.exe

Worm:Win32/Vobfus.CT also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Symmi.5242
ClamAVWin.Trojan.VB-1758
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeVBObfus.g
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.VbCryptGen.Win32.1
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.638E724F20
VirITWorm.Win32.Generic.AUTS
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.AHJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.WBNA.ipa
BitDefenderGen:Variant.Symmi.5242
NANO-AntivirusTrojan.Win32.VBKrypt.cmxrud
AvastWin32:VB-ABDC [Drp]
TencentWorm.Win32.Wbna.zb
EmsisoftGen:Variant.Symmi.5242 (B)
BaiduWin32.Worm.Pronny.d
F-SecureTrojan.TR/Dropper.VB.Gen
DrWebWin32.HLLW.Autoruner3.6104
VIPREGen:Variant.Symmi.5242
TrendMicroWORM_VBNA.SMVI
SophosMal/SillyFDC-T
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/Dropper.VB.Gen
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftWorm:Win32/Vobfus.CT
ArcabitTrojan.Symmi.D147A
ZoneAlarmWorm.Win32.WBNA.ipa
GDataGen:Variant.Symmi.5242
VaristW32/VBKrypt.BGS.gen!Eldorado
AhnLab-V3Trojan/Win32.VBKrypt.R77773
Acronissuspicious
VBA32BScope.Trojan-Dropper.VB.01545
ALYacGen:Variant.Symmi.5242
TACHYONTrojan/W32.VB-VBKrypt.122880.BW
Cylanceunsafe
TrendMicro-HouseCallWORM_VBNA.SMVI
RisingWorm.Pronny!1.B1A8 (CLASSIC)
IkarusGen.Variant.VBKrypt
FortinetW32/VBObfus.G!tr
AVGWin32:VB-ABDC [Drp]
Cybereasonmalicious.dc6e72
DeepInstinctMALICIOUS

How to remove Worm:Win32/Vobfus.CT?

Worm:Win32/Vobfus.CT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment