Worm

Should I remove “Worm:Win32/Vobfus.FK”?

Malware Removal

The Worm:Win32/Vobfus.FK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.FK virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm:Win32/Vobfus.FK?


File Info:

name: 29CE0DEDA05DF0ED4E1A.mlw
path: /opt/CAPEv2/storage/binaries/b6559b22c1e38e275f4dabb4b7784ee01a172bb3590f8203a1f457c5b56c9429
crc32: D792F316
md5: 29ce0deda05df0ed4e1a7396722cd9db
sha1: f6a6e7a4dda4242639f19bd1a1ac03c6e815bee8
sha256: b6559b22c1e38e275f4dabb4b7784ee01a172bb3590f8203a1f457c5b56c9429
sha512: 43251601e375138cc13b31f454d310840523c014c9c30c8acfc1ba08c2844a25ed2b55e03a6a4fe2412702ae00e8aaa47400c1abbe1b592b64ddf449b73280db
ssdeep: 6144:eYdCMeavuzakX681UbgwDO7zRdmM57M1864FGH:eEBvuzPEH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T122644F20B748AB73E5CA95B53347C1E52BA9BE0D5F7B90CDB2003BB89C51F649DA4207
sha3_384: 58c0fb775c3fd1a6d38e8e70b43afb47658be0fa74845d718c269c490b08fab3f24a83a08c6ab6f099e309cc79493efc
ep_bytes: 68ec124000e8eeffffff000048000000
timestamp: 2012-05-31 21:50:15

Version Info:

Translation: 0x0409 0x04b0
Comments: Demo For the isButton Control Version 3
CompanyName: Fred.cpp Productions
FileDescription: Test For the IsButton Control by Fred.cpp
LegalCopyright: Fred.cpp Productions
LegalTrademarks: Fred.cpp Productions
ProductName: isButton test
FileVersion: 1.00.0058
ProductVersion: 1.00.0058
InternalName: oemwohzj
OriginalFilename: oemwohzj.exe

Worm:Win32/Vobfus.FK also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner2.15207
MicroWorld-eScanGen:Variant.Barys.4115
ClamAVWin.Trojan.Changeup-6169544-0
FireEyeGeneric.mg.29ce0deda05df0ed
CAT-QuickHealWorm.VbnaMF.S27266060
SkyhighBehavesLike.Win32.VBObfus.fm
McAfeeW32/Autorun.worm.aaeh
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Barys.4115
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 003c363a1 )
AlibabaWorm:Win32/Vobfus.cb183bb6
K7GWEmailWorm ( 003c363a1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZevbaF.36744.sm0@ayEXxRfi
VirITTrojan.Win32.VBCrypt.EVF
SymantecW32.Changeup
ESET-NOD32Win32/AutoRun.VB.BKV
ZonerTrojan.Win32.86769
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.WBNA.ipa
BitDefenderGen:Variant.Barys.4115
NANO-AntivirusTrojan.Win32.VB.cqkxsi
SUPERAntiSpywareTrojan.Agent/Gen-Autogen
AvastWin32:VB-ADDH [Trj]
TencentWorm.Win32.Vbna.bo
TACHYONWorm/W32.WBNA.307200
SophosMal/Chuckee-A
F-SecureTrojan.TR/Jorik.enuxbb
BaiduWin32.Worm.Autorun.t
TrendMicroWORM_VOBFUS.SM01
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Barys.4115 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Barys.4115
WebrootW32.Malware.gen
GoogleDetected
AviraTR/Jorik.enuxbb
Antiy-AVLWorm/Win32.WBNA.gen
KingsoftWin32.HeurC.KVM007.a
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Barys.D1013
ZoneAlarmWorm.Win32.WBNA.ipa
MicrosoftWorm:Win32/Vobfus.FK
VaristW32/Vobfus.AQ.gen!Eldorado
AhnLab-V3Trojan/Win32.Jorik.R26313
VBA32TScope.Trojan.VB
ALYacGen:Variant.Barys.4115
MAXmalware (ai score=81)
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallWORM_VOBFUS.SM01
RisingWorm.AutoRun!8.50 (CLOUD)
YandexTrojan.GenAsa!vaQm8u79YAQ
IkarusWorm.Win32.Vobfus
FortinetW32/VBObfus.C!tr
AVGWin32:VB-ADDH [Trj]
Cybereasonmalicious.4dda42
DeepInstinctMALICIOUS

How to remove Worm:Win32/Vobfus.FK?

Worm:Win32/Vobfus.FK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment