Worm

Worm:Win32/Vobfus.FQ removal instruction

Malware Removal

The Worm:Win32/Vobfus.FQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.FQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Vobfus.FQ?


File Info:

name: 7C2A5484A87A033000CD.mlw
path: /opt/CAPEv2/storage/binaries/2685d381af64b9a5d60a703e48777e478bdee38e85adcf8022f2b7e87d717c34
crc32: 6167B6A8
md5: 7c2a5484a87a033000cd617a08d397b6
sha1: 020b8402a5a9242c8dac833267b3e7bcf68609f1
sha256: 2685d381af64b9a5d60a703e48777e478bdee38e85adcf8022f2b7e87d717c34
sha512: 24caaca78d9b0dd6f6dc3dae7115d5dff2df620b3019ab73b9f5769085f5c311f174dcd0d586d6f2a2d5fd6945ad332cadc6329955319b3d3a37b3a4644866b8
ssdeep: 1536:A5WAvSI3wccoAeiCX6tEG7a9GjB4tnYmy1DZeKfw:oSeqCXKgGjYnBy1zw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13BF39216B751D811D6685137DEA7D2FA66B6BC4A9F07A20FBA10375F3CB2F006C10A93
sha3_384: a3720679c80f6e054d460232e2c78aaaa9190b483b44e8c736018502eec51c8e28de23d5e1a83a3b5bfc12cd2d79c8cc
ep_bytes: 68c4124000e8eeffffff000000000000
timestamp: 2012-06-20 04:16:11

Version Info:

Translation: 0x0409 0x04b0
Comments: evangelic appreciatingly
CompanyName: evangelic appreciatingly
FileDescription: evangelic appreciatingly
LegalCopyright: evangelic appreciatingly
LegalTrademarks: evangelic appreciatingly
ProductName: evangelic appreciatingly
FileVersion: 2.04
ProductVersion: 2.04
InternalName: alcuzecljq
OriginalFilename: alcuzecljq.exe

Worm:Win32/Vobfus.FQ also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lCqw
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Changeup-6169544-0
CAT-QuickHealWorm.WbnaMF.S18680737
SkyhighBehavesLike.Win32.VBObfus.ct
ALYacWin32.Worm.VB.OAE
MalwarebytesGeneric.Worm.AutoRun.DDS
VIPREWin32.Worm.VB.OAE
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
BitDefenderWin32.Worm.VB.OAE
K7GWEmailWorm ( 003c363a1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Worm.VB.pm
VirITTrojan.Win32.VB.E
SymantecW32.Changeup
ESET-NOD32a variant of Win32/AutoRun.VB.AWX
APEXMalicious
AvastWin32:VB-ADDH [Trj]
CynetMalicious (score: 100)
KasperskyWorm.Win32.WBNA.ipa
AlibabaWorm:Win32/Vobfus.d50effb2
NANO-AntivirusTrojan.Win32.Vobfus.cnwqsp
MicroWorld-eScanWin32.Worm.VB.OAE
RisingWorm.Autorun!1.DA89 (CLASSIC)
EmsisoftWin32.Worm.VB.OAE (B)
F-SecureTrojan.TR/Rogue.kdj.6
DrWebWin32.HLLW.Autoruner1.17570
ZillyaWorm.WBNA.Win32.710679
TrendMicroWORM_VOBFUS.SMDX
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.7c2a5484a87a0330
SophosMal/Vobfus-I
SentinelOneStatic AI – Malicious PE
JiangminWorm.WBNA.lepw
WebrootW32.Obfuscated.Gen
GoogleDetected
AviraTR/Rogue.kdj.6
MAXmalware (ai score=85)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.996
MicrosoftWorm:Win32/Vobfus.FQ
XcitiumTrojWare.Win32.AutoRun.ANT@4mtxpu
ArcabitWin32.Worm.VB.OAE
SUPERAntiSpywareTrojan.Agent/Gen-Vban
ZoneAlarmWorm.Win32.WBNA.ipa
GDataWin32.Worm.VB.OAE
VaristW32/Vobfus.AQ.gen!Eldorado
AhnLab-V3Worm/Win32.WBNA.R28275
McAfeeVBObfus.ek
TACHYONWorm/W32.WBNA.163840.B
DeepInstinctMALICIOUS
VBA32TScope.Trojan.VB
Cylanceunsafe
TrendMicro-HouseCallWORM_VOBFUS.SMDX
TencentWorm.Win32.Vobfus.n
YandexTrojan.GenAsa!9jsV86g+4QE
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.AU!tr
BitDefenderThetaGen:NN.ZevbaF.36680.km0@a8Infoii
AVGWin32:VB-ADDH [Trj]
Cybereasonmalicious.2a5a92
PandaW32/Vobfus.GEW.worm

How to remove Worm:Win32/Vobfus.FQ?

Worm:Win32/Vobfus.FQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment