Worm

Worm:Win32/Vobfus.EY removal instruction

Malware Removal

The Worm:Win32/Vobfus.EY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.EY virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Vobfus.EY?


File Info:

name: 51C31D6AD535D32D2ED3.mlw
path: /opt/CAPEv2/storage/binaries/4794fe1da0c72958ce9e770bba5b24a112cda1946925980dbcc0d2f86885daf1
crc32: A4A0B1EF
md5: 51c31d6ad535d32d2ed39145a0937639
sha1: e8e47224d963cd9327f6fb91066a731226c7b4e4
sha256: 4794fe1da0c72958ce9e770bba5b24a112cda1946925980dbcc0d2f86885daf1
sha512: f644fe8bf16942897d8a42dd5b59346cf30609da3f9d418f68b880de823a5732b3f6f78e555852ffed1e79871b4637cc308694f7ea5c34b0779824ab970358d4
ssdeep: 3072:cm38bUQSxVjJhU8hPsOkfJeJ7JwJHJ6JkBTriGXfXkGN3tqZ4xoRg4Sx+TidczfS:VUUBJhhEop2pYOF0yIdgFGw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13644E8733FA11649F46C487459F286F523E7A80F8A47404B76E022E96EFBE361D246D3
sha3_384: cbd5c611d57939aa33fb3201c2a5845661fd190dabca9d9ef9b9ed915756a59d92ad31b50707b5d6637515fe000326d5
ep_bytes: 68ec124000e8eeffffff000048000000
timestamp: 2012-05-08 20:39:20

Version Info:

Translation: 0x0409 0x04b0
ProductName: lzyuhcuajz
FileVersion: 7.08.0002
ProductVersion: 7.08.0002
InternalName: qixlibnpvatb
OriginalFilename: qixlibnpvatb.exe

Worm:Win32/Vobfus.EY also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Vobfus.t!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Barys.2490
FireEyeGeneric.mg.51c31d6ad535d32d
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
ALYacGen:Variant.Barys.2490
Cylanceunsafe
SangforVirus.Win32.Save.a
K7AntiVirusEmailWorm ( 003c363a1 )
AlibabaWorm:Win32/Vobfus.e02396e8
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.ad535d
BitDefenderThetaGen:NN.ZevbaF.36802.pm1@aqhYWyci
VirITTrojan.Win32.Zyx.KI
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.AVS
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMJA
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyEmail-Worm.Win32.VB.aaf
BitDefenderGen:Variant.Barys.2490
NANO-AntivirusTrojan.Win32.Vobfus.chzvjr
SUPERAntiSpywareTrojan.Agent/Gen-Vban
AvastWin32:VB-ACSO [Trj]
TACHYONTrojan/W32.VB-Agent.253954.B
EmsisoftGen:Variant.Barys.2490 (B)
BaiduWin32.Worm.VB.lw
F-SecureWorm.WORM/Vobfus.EY.JH.2
DrWebTrojan.DownLoader6.6377
VIPREGen:Variant.Barys.2490
TrendMicroWORM_VOBFUS.SMJA
Trapminemalicious.high.ml.score
SophosMal/VBCheMan-G
IkarusWorm.Win32.Vobfus
JiangminTrojan/Vbobf.b
GoogleDetected
AviraWORM/Vobfus.EY.JH.2
VaristW32/Vobfus.AQ.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus.EY
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Barys.D9BA
ZoneAlarmEmail-Worm.Win32.VB.aaf
GDataGen:Variant.Barys.2490
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R25213
Acronissuspicious
McAfeeGenericRXEX-NE!51C31D6AD535
MAXmalware (ai score=89)
VBA32Worm.VB
MalwarebytesGeneric.Malware.AI.DDS
RisingWorm.VobfusEx!1.99DC (CLASSIC)
YandexTrojan.GenAsa!lNcOHWDDIsw
SentinelOneStatic AI – Malicious PE
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-ACSO [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudWorm:Win/Vobfus.da936ce1

How to remove Worm:Win32/Vobfus.EY?

Worm:Win32/Vobfus.EY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment