Worm

Worm:Win32/Vobfus.EV information

Malware Removal

The Worm:Win32/Vobfus.EV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.EV virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Sindhi
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Vobfus.EV?


File Info:

name: 15BC882D9CA360C44639.mlw
path: /opt/CAPEv2/storage/binaries/6817dbd53a293cb811f865f9b1a4e707b3398f07c04dfd552d552b4899289081
crc32: CB70E2F9
md5: 15bc882d9ca360c446390f4d892d3337
sha1: 63588c937b85a03fab13515db804924ef14eeeec
sha256: 6817dbd53a293cb811f865f9b1a4e707b3398f07c04dfd552d552b4899289081
sha512: 270f0fc3f5387192730a30ca8ddd385ef81cf7ba896706bf865caad9ff488b7bc154a3ac7e14554be74cd60ab320e35778e839fbbf22f5a57dd7aa82e1e617e3
ssdeep: 6144:zEM3PFKs7aaOKW8alhrEqxF6snji81RUinKGHgD9F:zEWPhvENPH6H
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13A34B7A77F649948F53A15F458F3C3F21292E84CCA47420B5B703A2A2EFBE461D24673
sha3_384: 6c70f86f3b38b5fa819e58e8bfb558f077b068ead2832ae37cdd95483be2a22f1191538821c9d357aa77216a6f67856e
ep_bytes: 68a0124000e8f0ffffff000000000000
timestamp: 2012-05-03 05:54:34

Version Info:

Translation: 0x0409 0x04b0
ProductName: ygdswncosxk
FileVersion: 7.08.0002
ProductVersion: 7.08.0002
InternalName: lqoadcbxmb
OriginalFilename: lqoadcbxmb.exe

Worm:Win32/Vobfus.EV also known as:

BkavW32.AIDetectMalware
AVGWin32:VB-ACQU [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.VBInject.11
FireEyeGeneric.mg.15bc882d9ca360c4
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dt
McAfeeVBObfus.dv
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
K7GWEmailWorm ( 003c363a1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Worm.VB.aq
VirITTrojan.Win32.VBCrypt.EVL
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.AVM
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:VB-ACQU [Trj]
ClamAVWin.Malware.Vobfus-9940378-0
KasperskyWorm.Win32.Vobfus.dgsd
BitDefenderGen:Variant.VBInject.11
NANO-AntivirusTrojan.Win32.VB.rilqk
TencentWorm.Win32.Vobfus.n
EmsisoftGen:Variant.VBInject.11 (B)
F-SecureTrojan.TR/Barys.992.JH.2
DrWebWin32.HLLW.Autoruner1.15339
TrendMicroWORM_VOBFUS.SMJ2
Trapminemalicious.high.ml.score
SophosW32/SillyFD-W
IkarusTrojan.Win32.Vobfus
GDataGen:Variant.VBInject.11
JiangminTrojan/Generic.atfxu
VaristW32/Vobfus.O.gen!Eldorado
AviraTR/Barys.992.JH.2
MAXmalware (ai score=81)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.996
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.VBInject.11
ViRobotTrojan.Win32.A.VB.233472.N
ZoneAlarmWorm.Win32.Vobfus.dgsd
MicrosoftWorm:Win32/Vobfus.EV
GoogleDetected
AhnLab-V3Trojan/Win32.VB.R24513
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36802.om0@amzR9siO
ALYacGen:Variant.VBInject.11
TACHYONWorm/W32.Vobfus.233472.B
VBA32SScope.Malware-Cryptor.VBCR.3042
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMJ2
RisingTrojan.FakeIcon!1.64A2 (CLASSIC)
YandexTrojan.GenAsa!MsRL0fxcwn8
SentinelOneStatic AI – Malicious PE
FortinetW32/VBObfus.AU!tr
Cybereasonmalicious.d9ca36
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Vobfus.e6934207

How to remove Worm:Win32/Vobfus.EV?

Worm:Win32/Vobfus.EV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment