Worm

Worm:Win32/Vobfus.DR removal tips

Malware Removal

The Worm:Win32/Vobfus.DR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.DR virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Vobfus.DR?


File Info:

name: A10474BA6EF0EE4775DB.mlw
path: /opt/CAPEv2/storage/binaries/172b56d6b9c477e10cce23828462a33eb5ebc40864b75c4d29f8bc33804e1521
crc32: 8E278359
md5: a10474ba6ef0ee4775dbfa09278c55e6
sha1: cc53d9a8b85022fd757bda24eb7cb011cdbacadf
sha256: 172b56d6b9c477e10cce23828462a33eb5ebc40864b75c4d29f8bc33804e1521
sha512: 5218c5a64c190c5f9be77949baf339e6a2bb58d461a0aacaa0006e57e9bedcde2f0d26504e3abc171f6dfd4a827e8da28d43049d2f04df5ddc653260a223c541
ssdeep: 3072:t6CwPe4oJDKPTroUqBGU/WJ8PcsZ2h3PDp:trae4oJDK7roUqBGU/WJ8l2x
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17FA3A22B779411E3D52882F52DC7B7C355B222861A2779831E201796FC2AE120B7D9FF
sha3_384: 6e6484397395e1872d2f0471e6f7c5c2c8d82f6d5d1776b7c59b7f19c450be884978c7124ed7c4f287117507582d28b2
ep_bytes: 6848134000e8f0ffffff000000000000
timestamp: 2011-02-19 04:09:25

Version Info:

Translation: 0x0409 0x04b0
ProductName: GZwciICbgXlmAlxFeOd
FileVersion: 2.96
ProductVersion: 2.96
InternalName: KutGk
OriginalFilename: KutGk.exe

Worm:Win32/Vobfus.DR also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.VBKrypt.lkoQ
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.VBKrypt.55
FireEyeGeneric.mg.a10474ba6ef0ee47
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeVBObfus.f
Cylanceunsafe
ZillyaWorm.WBNA.Win32.1427308
SangforSuspicious.Win32.Save.vb
K7AntiVirusNetWorm ( 700000151 )
AlibabaWorm:Win32/Vobfus.1dd2eeb2
K7GWNetWorm ( 700000151 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.8C64108D20
VirITTrojan.Win32.VB.KV
SymantecW32.Changeup!gen10
ESET-NOD32a variant of Win32/AutoRun.VB.ABI
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMIA
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.WBNA.ipa
BitDefenderGen:Variant.VBKrypt.55
NANO-AntivirusTrojan.Win32.VBKrypt.covkbs
SUPERAntiSpywareTrojan.Agent/Gen-Frauder
AvastWin32:VB-RJS [Drp]
TencentMalware.Win32.Gencirc.13c13560
EmsisoftGen:Variant.VBKrypt.55 (B)
BaiduWin32.Worm.AutoRun.cj
F-SecureTrojan.TR/Dropper.VB.Gen
DrWebTrojan.DownLoader17.35709
VIPREGen:Variant.VBKrypt.55
TrendMicroWORM_VOBFUS.SMIA
Trapminemalicious.moderate.ml.score
SophosMal/SillyFDC-C
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.VBKrypt.55
GoogleDetected
AviraTR/Dropper.VB.Gen
VaristW32/Vobfus.O.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.VBNA.AZX@4zfie0
ArcabitTrojan.VBKrypt.55
ViRobotTrojan.Win32.A.VBKrypt.106496.C
ZoneAlarmWorm.Win32.WBNA.ipa
MicrosoftWorm:Win32/Vobfus.DR
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/VBKrypt.Gen
VBA32Trojan.VBRA.011030
ALYacGen:Variant.VBKrypt.55
MAXmalware (ai score=100)
MalwarebytesMalware.AI.3985429945
PandaTrj/Genetic.gen
RisingWorm.VobfusEx!1.99EB (CLASSIC)
YandexTrojan.GenAsa!QU2XOJneHI0
IkarusTrojan.Win32.VBKrypt
FortinetW32/AutoRun.XM!worm
AVGWin32:VB-RJS [Drp]
Cybereasonmalicious.a6ef0e
DeepInstinctMALICIOUS
alibabacloudWorm:Win/WBNA.ipa

How to remove Worm:Win32/Vobfus.DR?

Worm:Win32/Vobfus.DR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment