Worm

Worm:Win32/Vobfus.DW removal instruction

Malware Removal

The Worm:Win32/Vobfus.DW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.DW virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Vobfus.DW?


File Info:

name: 5A72A7EBA15AC00CD159.mlw
path: /opt/CAPEv2/storage/binaries/87c6009d1e63398f52f2bf34cb6a013674714c71b32ac07316f054fbe9697f1f
crc32: 915FD75E
md5: 5a72a7eba15ac00cd1595f54a825b408
sha1: 0cd1a4e90a56c8bebd5a1b6d864d04a93dbed7d7
sha256: 87c6009d1e63398f52f2bf34cb6a013674714c71b32ac07316f054fbe9697f1f
sha512: 46dd5b1e9a9445aba57b65a6e60b14b23984ac250c162945ab703845bb8a78a51092b1ad5be8456193adb1c4314fb64bd3742d4f8abdb8751fbd195b7a115807
ssdeep: 3072:13EaE8iYN/UpD+cu5p0fZahWA69l2zzk1wV4Ghq4ibRSWoBEtazeV5bo9f:13HUYdWD+cZ1wV45o6tazeVUf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BB6440797241BE3AD112D7F4E8795790501C9EF60A946427FFC2362622F98E2B21CF93
sha3_384: 47d3a3015155d30c8db2a7a3f257d822a48bbfdfefddc10a64349d03dacaae953f08c68761cd7b49f3a05d88366d96fd
ep_bytes: 68a43d4000e8f0ffffff000048000000
timestamp: 2012-02-23 02:53:09

Version Info:

0: [No Data]

Worm:Win32/Vobfus.DW also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Sirefef.942
FireEyeGeneric.mg.5a72a7eba15ac00c
CAT-QuickHealWorm.WbnaVMF.S20620518
ALYacGen:Variant.Sirefef.942
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Sirefef.942
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.ba15ac
BaiduWin32.Trojan.Inject.n
VirITTrojan.Win32.Zyx.JI
CyrenW32/Vobfus.AG.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/Pronny.AD
APEXMalicious
ClamAVWin.Trojan.Vobfus-43
KasperskyWorm.Win32.WBNA.ipa
BitDefenderGen:Variant.Sirefef.942
NANO-AntivirusTrojan.Win32.VBKrypt.covjzl
SUPERAntiSpywareTrojan.Agent/Gen-Autogen
AvastWin32:VB-ABKM [Trj]
TencentWorm.Win32.Vobfus.n
TACHYONWorm/W32.WBNA.335872.D
SophosMal/SillyFDC-W
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.VbCrypt.60
TrendMicroWORM_VOBFUS.SMAB
McAfee-GW-EditionBehavesLike.Win32.VBObfus.ft
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Sirefef.942 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Worm.Vobfus.T7XVPZ
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.VB.JZ@4nqqav
ArcabitTrojan.Sirefef.942
ViRobotTrojan.Win32.A.VBKrypt.335872.BO
ZoneAlarmWorm.Win32.WBNA.ipa
MicrosoftWorm:Win32/Vobfus.DW
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.WBNA.R21378
VBA32BScope.Trojan.VB.Diple.01583
MAXmalware (ai score=85)
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMAB
RisingWorm.VobfusEx!1.99DB (CLASSIC)
IkarusWorm.Win32.Vobfus
FortinetW32/VBKrypt.C!tr
BitDefenderThetaGen:NN.ZevbaF.36302.umW@a8J7ZHki
AVGWin32:VB-ABKM [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Vobfus.DW?

Worm:Win32/Vobfus.DW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment