Worm

Worm:Win32/Vobfus.DM removal tips

Malware Removal

The Worm:Win32/Vobfus.DM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.DM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm:Win32/Vobfus.DM?


File Info:

name: F95F2729E9FB573667FE.mlw
path: /opt/CAPEv2/storage/binaries/11719f182beedd0ed47d5f0b840aa14484a7839a992ec9cec777a09bfc055569
crc32: 71CC69EC
md5: f95f2729e9fb573667fe694a7dec22c0
sha1: 6aa5491b72ac52f1a01eac7ad9c604be0f186382
sha256: 11719f182beedd0ed47d5f0b840aa14484a7839a992ec9cec777a09bfc055569
sha512: 9a75dc8fb8681e0a433df4d90d89df08cb2be6ccbe485911b2b34263e563f50e2d7a267eb8b6335ea4849b09137c10f58bad843dcbd52c7715ae9c42dbe419d5
ssdeep: 6144:gkrD1y0FXrKnvmb7/D26OJYPsMiqDJlJNwHG60Ja20EBb4jHX3QA/hwNGhWhThPJ:g4D1y0F7Knvmb7/D265DJlJNwHG6sTb/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C1544317FB00A11AF56248F03A2DAB965D292D373650BC07BB835B1865B16DBB8F071F
sha3_384: ad999150e2fbb33815f53f0f4cd714a41869ce4a375d8d6393b1914a832715f749082e73067fb4df0685a0e9fe84eafc
ep_bytes: 68783b4000e8eeffffff000000000000
timestamp: 2011-10-27 18:35:06

Version Info:

0: [No Data]

Worm:Win32/Vobfus.DM also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.luev
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.67005726
FireEyeGeneric.mg.f95f2729e9fb5736
CAT-QuickHealWorm.VobfusVMF.S28965266
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.bs
Cylanceunsafe
ZillyaWorm.Vobfus.Win32.1208114
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Vobfus.f390e127
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.9e9fb5
BitDefenderThetaAI:Packer.6BC4D2BA20
VirITTrojan.Win32.Zyx.FJ
SymantecW32.Changeup.C
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.AOK
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMAC
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.ddva
BitDefenderTrojan.GenericKD.67005726
NANO-AntivirusTrojan.Win32.WBNA.cqkxpd
AvastWin32:WormX-gen [Wrm]
TencentWorm.Win32.Vobfus.n
TACHYONWorm/W32.Vobfus.303104
EmsisoftTrojan.GenericKD.67005726 (B)
BaiduWin32.Worm.Autorun.l
F-SecureTrojan.TR/Spy.Agent.303121
DrWebTrojan.VbCrypt.60
VIPRETrojan.GenericKD.67005726
TrendMicroWORM_VOBFUS.SMAC
Trapminemalicious.moderate.ml.score
SophosMal/SillyFDC-T
IkarusWorm.Win32.Vobfus
GoogleDetected
AviraTR/Spy.Agent.303121
VaristW32/Vobfus.Z.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.999
MicrosoftWorm:Win32/Vobfus.DM
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Generic.D3FE6D1E
ZoneAlarmWorm.Win32.Vobfus.ddva
GDataTrojan.GenericKD.67005726
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Diple.R15226
Acronissuspicious
VBA32BScope.Trojan.Menti
ALYacTrojan.GenericKD.67005726
MAXmalware (ai score=80)
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.GEW.worm
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!VQxTR22XDp8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Menti.ioif
FortinetW32/VB.ADV!tr
AVGWin32:WormX-gen [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan[spy]:Win/Vobfus.1a62ef3f

How to remove Worm:Win32/Vobfus.DM?

Worm:Win32/Vobfus.DM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment