Categories: Worm

How to remove “Worm:Win32/Vobfus.FO”?

The Worm:Win32/Vobfus.FO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.FO virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm:Win32/Vobfus.FO?


File Info:

name: 32F5AB42DDB682C89E1B.mlwpath: /opt/CAPEv2/storage/binaries/99a099e376fd5212e18bf5ad594ad8c10e2a12108c523cffb55b417342e8b015crc32: 86F28580md5: 32f5ab42ddb682c89e1b6b28b66d9580sha1: 4896c3e7586de285a5090c5a4784bb33eebe7f20sha256: 99a099e376fd5212e18bf5ad594ad8c10e2a12108c523cffb55b417342e8b015sha512: 2a06298f6513f473c99ace93c4b61680384f91d841438f2388b1d069f2289cf626e642c196102657852ecf5f2df4096881b3780a65645bbdd99733bc23129ffessdeep: 3072:dKjcAJasck6HR1kT+SCBT2KD0gwcJ1USgyavhmVizMpbjyv8+/w:dNSasckgH++SCNvFwcJ1USgya5Y6Mpb1type: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T196041935A994907FE0A3D6F0687CD39629292D3A13D4EC4766E1AB0864701F7B6F231Fsha3_384: 607d1173030ccf91aaa5e31960df5bbef3fa1e97736d0f68616220f0a57f22b9ae84bc885c7e51706d59970e20fc4574ep_bytes: 6880474000e8eeffffff000058000000timestamp: 2012-06-18 02:18:36

Version Info:

Translation: 0x0409 0x04b0Comments: afterwrist xeronic TeucriumCompanyName: OmniparentFileDescription: Subordinary pyelectasisLegalCopyright: panoramical Praecocial AccanendoLegalTrademarks: TypomaniaProductName: Coxcombical wadding diaspidineFileVersion: 7.07ProductVersion: 7.07InternalName: zgtfkivnwiecqolyOriginalFilename: zgtfkivnwiecqoly.exe

Worm:Win32/Vobfus.FO also known as:

Bkav W32.AIDetectMalware
MicroWorld-eScan Gen:Variant.VBInject.11
ClamAV Win.Trojan.Vobfus-4
CAT-QuickHeal Trojan.Beebone.D
ALYac Gen:Variant.VBInject.11
Malwarebytes Pronny.Worm.Spreader.DDS
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (D)
K7GW EmailWorm ( 0054d10f1 )
K7AntiVirus EmailWorm ( 0054d10f1 )
Baidu Win32.Trojan.VBObfus.f
VirIT Worm.Win32.VB.CJAV
Cyren W32/Vobfus.BE.gen!Eldorado
Symantec W32.Changeup
Elastic malicious (high confidence)
ESET-NOD32 Win32/Pronny.JX
APEX Malicious
Cynet Malicious (score: 100)
Kaspersky Worm.Win32.VB.ebi
BitDefender Gen:Variant.VBInject.11
NANO-Antivirus Trojan.Win32.WBNA.csnmnk
SUPERAntiSpyware Trojan.Agent/Gen-Vban
Avast Win32:VB-ADKF [Trj]
Tencent Worm.Win32.Vobfus.n
TACHYON Worm/W32.Agent.188416
Emsisoft Gen:Variant.VBInject.11 (B)
F-Secure Trojan.TR/Dropper.Gen
DrWeb Trojan.VbCrypt.60
VIPRE Gen:Variant.VBInject.11
TrendMicro WORM_VOBFUS.NY
McAfee-GW-Edition BehavesLike.Win32.VBObfus.cm
Trapmine malicious.high.ml.score
FireEye Generic.mg.32f5ab42ddb682c8
Sophos Mal/SillyFDC-W
SentinelOne Static AI – Malicious PE
GData Gen:Variant.VBInject.11
Jiangmin Trojan/Vbobf.b
Avira TR/Dropper.Gen
Antiy-AVL Worm/Win32.WBNA.gen
Xcitium Worm.Win32.Pronny.AK@4ogvoo
Arcabit Trojan.VBInject.11
ViRobot Worm.Win32.A.VB.188416.A
ZoneAlarm Worm.Win32.VB.ebi
Microsoft Worm:Win32/Vobfus.FO
Google Detected
AhnLab-V3 Worm/Win32.WBNA.R27996
McAfee VBObfus.el
MAX malware (ai score=80)
VBA32 BScope.Trojan.VB.Onechki
Cylance unsafe
Panda W32/Vobfus.GEW.worm
TrendMicro-HouseCall WORM_VOBFUS.NY
Rising Worm.AutoRun!1.E3CB (CLASSIC)
Yandex Trojan.GenAsa!Nz3cELyFUVE
Ikarus Worm.Win32.Vobfus
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/VBKrypt.C!tr
BitDefenderTheta Gen:NN.ZevbaF.36196.lm0@amnitIdi
AVG Win32:VB-ADKF [Trj]
Cybereason malicious.2ddb68
DeepInstinct MALICIOUS

How to remove Worm:Win32/Vobfus.FO?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

Should I remove “Razy.448479”?

The Razy.448479 is considered dangerous by lots of security experts. When this infection is active,…

5 mins ago

Malware.AI.4243810870 removal tips

The Malware.AI.4243810870 is considered dangerous by lots of security experts. When this infection is active,…

20 mins ago

Trojan:Win32/Trickbot.PF!MTB malicious file

The Trojan:Win32/Trickbot.PF!MTB is considered dangerous by lots of security experts. When this infection is active,…

21 mins ago

How to remove “Malware.AI.1899226952”?

The Malware.AI.1899226952 is considered dangerous by lots of security experts. When this infection is active,…

25 mins ago

Lazy.13485 information

The Lazy.13485 is considered dangerous by lots of security experts. When this infection is active,…

25 mins ago

Malware.AI.4200493585 information

The Malware.AI.4200493585 is considered dangerous by lots of security experts. When this infection is active,…

25 mins ago