Worm

Worm:Win32/Vobfus.DE removal guide

Malware Removal

The Worm:Win32/Vobfus.DE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.DE virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Sniffs keystrokes
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Anomalous binary characteristics

How to determine Worm:Win32/Vobfus.DE?


File Info:

crc32: ABAEA024
md5: da9ef5e10d8c216d269a355e9ce92c63
name: DA9EF5E10D8C216D269A355E9CE92C63.mlw
sha1: 4bef88873d6ce95ab015c1dd4ecfd65167466689
sha256: 3cf765206b00a817efda4a9a4eacfc162cac00c12802d03f8d5599354a78421a
sha512: a44475bf5dfc6086decd79f866cc74b5ba02a376536df05dd6cf45745b308e2d4790dc1a6efe9bff0b6c1b65b889184922f7dafce002617cfd588579005c8b8a
ssdeep: 6144:U41rmjxvbSNeP40p7W3lw8f/ykRbKxU1OFI/vLJWtt2uhYZ6ki/O:U4ZU5bSL0psf/IxyPnL+ouhKiG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: server
FileVersion: 5.00
CompanyName:
ProductName: Ymgsr
ProductVersion: 5.00
OriginalFilename: server.exe

Worm:Win32/Vobfus.DE also known as:

BkavW32.AIDetect.malware1
K7AntiVirusP2PWorm ( 00136f0d1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader5.41634
CynetMalicious (score: 100)
CAT-QuickHealTrojanRansom.Blocker
ALYacGen:Trojan.Heur.VP2.vqZ@aKvTykg
CylanceUnsafe
ZillyaWorm.AutoRun.Win32.133628
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Blocker.9a9345dd
K7GWP2PWorm ( 00136f0d1 )
Cybereasonmalicious.10d8c2
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/AutoRun.PSW.VB.H
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Cospet-6726573-0
KasperskyTrojan-Ransom.Win32.Blocker.hdzg
BitDefenderGen:Trojan.Heur.VP2.vqZ@aKvTykg
NANO-AntivirusTrojan.Win32.Blocker.errfhv
MicroWorld-eScanGen:Trojan.Heur.VP2.vqZ@aKvTykg
TencentMalware.Win32.Gencirc.10b58f5d
Ad-AwareGen:Trojan.Heur.VP2.vqZ@aKvTykg
SophosMal/Generic-S
ComodoMalware@#2lza657t22kss
BitDefenderThetaAI:Packer.C4D808811F
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.fh
FireEyeGeneric.mg.da9ef5e10d8c216d
EmsisoftGen:Trojan.Heur.VP2.vqZ@aKvTykg (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Spy.Gen
eGambitRAT.LostDoor
MicrosoftWorm:Win32/Vobfus.DE
AegisLabTrojan.Win32.Blocker.j!c
ZoneAlarmTrojan-Ransom.Win32.Blocker.hdzg
GDataGen:Trojan.Heur.VP2.vqZ@aKvTykg
AhnLab-V3Trojan/Win32.Cospet.R2764
McAfeeGenericRXAA-AA!DA9EF5E10D8C
MAXmalware (ai score=100)
VBA32BScope.Worm.WBNA
MalwarebytesMalware.AI.4260108780
PandaGeneric Suspicious
RisingBackdoor.LostDoor!1.CB41 (CLOUD)
YandexTrojan.GenAsa!TE5uEd2Ev0s
IkarusTrojan-PWS.Win32.VB
FortinetW32/Blocker.HDZ!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASOkA

How to remove Worm:Win32/Vobfus.DE?

Worm:Win32/Vobfus.DE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment