Worm

Worm:Win32/Vobfus.DC removal tips

Malware Removal

The Worm:Win32/Vobfus.DC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.DC virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Vobfus.DC?


File Info:

name: FA1A320FAE5113C83A1D.mlw
path: /opt/CAPEv2/storage/binaries/68bc713b27089ea0238ebf7fbf38dbd6c1f45f6e07061adfaf1cdeedc5905fff
crc32: D30464B8
md5: fa1a320fae5113c83a1dd0f3ec40091a
sha1: 4d89d6d9c1d8a0081d65aaa2769433c93a1f6f7c
sha256: 68bc713b27089ea0238ebf7fbf38dbd6c1f45f6e07061adfaf1cdeedc5905fff
sha512: f179c82deb3163f394a82217f57cd5b2b710676e7981c1da31de17793b70e3dee2f380ab2686983b928420323dc6258cc4d14d802495a8128c3cd43bdb5ddf06
ssdeep: 3072:VeD2qy7TBJVSgpS5uIyio/Conuh1CNvD1ae5V:VRqoTB2grko/C2gcQe5V
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DCD3A52A7290F23ECA15C6F5395A83B0906DAD3525D1AD03F3C66B1AB7F1DA7D260703
sha3_384: dac9f4e99a5ee7c07dee7c7327e36b2b4409a45193f6d7a1e5251019ec98ebd22c9e0474cdcec3745282cfdb86008668
ep_bytes: 68a0334000e8f0ffffff000000000000
timestamp: 2011-08-30 14:05:09

Version Info:

Translation: 0x0409 0x04b0
ProductName: mfOcfPKiGYOQqkYqY
FileVersion: 1.00
ProductVersion: 1.00
InternalName: FJUKsxBu
OriginalFilename: FJUKsxBu.exe

Worm:Win32/Vobfus.DC also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.luev
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.AXYK
ClamAVWin.Trojan.Vobfus-12
FireEyeGeneric.mg.fa1a320fae5113c8
CAT-QuickHealTrojan.Vobfus.gen
ALYacTrojan.Agent.AXYK
MalwarebytesGeneric.Worm.AutoRun.DDS
ZillyaWorm.Vobfus.Win32.1172957
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaMalware:Win32/km_2ff8.None
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.fae511
BaiduWin32.Worm.Pronny.d
VirITTrojan.Win32.Generic.SK
CyrenW32/Vobfus.V.gen!Eldorado
SymantecW32.Changeup!gen35
ESET-NOD32Win32/AutoRun.VB.AKU
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.efni
BitDefenderTrojan.Agent.AXYK
NANO-AntivirusTrojan.Win32.VBKrypt.covkxs
SUPERAntiSpywareTrojan.Agent/Gen-Vban
AvastWin32:VB-ABDC [Drp]
TencentWorm.Win32.Vobfus.n
TACHYONWorm/W32.Vobfus.135168
EmsisoftTrojan.Agent.AXYK (B)
F-SecureTrojan.TR/ATRAPS.Gen2
DrWebTrojan.VbCrypt.60
VIPRETrojan.Agent.AXYK
TrendMicroWORM_VOBFUS.SMAC
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.high.ml.score
SophosMal/VB-XV
IkarusTrojan.Spy.Agent
GDataWin32.Trojan.PSE.UNRGU8
AviraTR/ATRAPS.Gen2
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Agent.AXYK
ZoneAlarmWorm.Win32.Vobfus.efni
MicrosoftWorm:Win32/Vobfus.DC
GoogleDetected
AhnLab-V3Trojan/Win32.Diple.R23097
McAfeeVBObfus.at
MAXmalware (ai score=85)
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMAC
RisingWorm.VobfusEx!1.99DC (CLASSIC)
YandexTrojan.GenAsa!hnsWsW5eEPo
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.VB.ceo
FortinetW32/VBKrypt.C!tr
BitDefenderThetaAI:Packer.27E0F82020
AVGWin32:VB-ABDC [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Vobfus.DC?

Worm:Win32/Vobfus.DC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment