Worm

Worm:Win32/Vobfus.DP information

Malware Removal

The Worm:Win32/Vobfus.DP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.DP virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm:Win32/Vobfus.DP?


File Info:

name: 384F126F6CF61EE19D5D.mlw
path: /opt/CAPEv2/storage/binaries/3a6604349410b1207cd893390646e9baa57967388eac6bfca2ec748b0ba7e942
crc32: E1059B3B
md5: 384f126f6cf61ee19d5d844c4f8f9082
sha1: fb38a901fce0d7b9349e7bcb35c4d72ff9ab5f38
sha256: 3a6604349410b1207cd893390646e9baa57967388eac6bfca2ec748b0ba7e942
sha512: b74292a7418f951bcb807aa7e2d2db5306bdaac7dbcf302df72c524d57570f05f1f3cff433e54b1856c32b9017b4fd25c9923d2ce439877d711edc6c2c332cd0
ssdeep: 6144:lZDOfFrSU0bIaX/m7bfTWaJPGeyb7qh7wNAZBbM3f1:lZDOpSU0bIaX/m7bfTWaV1wWZBbM3f1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19B44C516BA11F06ED197C5F66939822635292D361691BC0B72C17F5E7BB0283B8F170F
sha3_384: 1824f8f07fe94961a7da285c91a622fea3c8aa93ee5c16fa0196d066b5cfd897d0d6666afdbdbda670fe8e0196963cf2
ep_bytes: 6808394000e8f0ffffff000000000000
timestamp: 1995-07-12 20:29:51

Version Info:

0: [No Data]

Worm:Win32/Vobfus.DP also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Virut.lJwt
MicroWorld-eScanGen:Variant.Zusy.459850
FireEyeGeneric.mg.384f126f6cf61ee1
CAT-QuickHealW32.Virut.G
McAfeeVBObfus.dq
MalwarebytesMalware.AI.3713972843
VIPREGen:Variant.Zusy.459850
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaMalware:Win32/km_2faa.None
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderThetaGen:NN.ZevbaF.36250.qqZ@aiKBFRf
VirITTrojan.Win32.Generic.CCVG
CyrenW32/Vobfus.AA.gen!Eldorado
SymantecW32.Changeup!gen15
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.APG
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.eeoq
BitDefenderGen:Variant.Zusy.459850
NANO-AntivirusTrojan.Win32.WBNA.cihugk
AvastWin32:Vitro [Inf]
TencentWorm.Win32.Vobfus.ks
TACHYONTrojan/W32.VB-Agent.274432.CL
SophosMal/VBCheMan-J
BaiduWin32.Worm.Autorun.l
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.VbCrypt.150
ZillyaWorm.Vobfus.Win32.1197902
TrendMicroCryp_VBNA-8
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dt
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zusy.459850 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.459850
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
ArcabitTrojan.Zusy.D7044A
ZoneAlarmWorm.Win32.Vobfus.eeoq
MicrosoftWorm:Win32/Vobfus.DP
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Vobfus.R185811
Acronissuspicious
VBA32BScope.Trojan.Diple
ALYacGen:Variant.Zusy.459850
MAXmalware (ai score=84)
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallCryp_VBNA-8
RisingWorm.Vobfus!8.10E (TFE:1:xI9XenCGlvT)
YandexTrojan.GenAsa!SVPuqe1JkvE
IkarusTrojan.Win32.Diple
FortinetW32/CoinMiner.F
AVGWin32:Vitro [Inf]
Cybereasonmalicious.f6cf61
DeepInstinctMALICIOUS

How to remove Worm:Win32/Vobfus.DP?

Worm:Win32/Vobfus.DP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment