Worm

Worm:Win32/Vobfus.FQ removal

Malware Removal

The Worm:Win32/Vobfus.FQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.FQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm:Win32/Vobfus.FQ?


File Info:

name: 0FE2A5A48DE2760A4DF4.mlw
path: /opt/CAPEv2/storage/binaries/5e0bb87d886217e81ab70bc2756e3b47e0519abd36b90f3f60354211c73e4ed1
crc32: 08E4FBEB
md5: 0fe2a5a48de2760a4df4fce0610d3381
sha1: 5677bf2a7a40f0309299da2317a975fab7fab351
sha256: 5e0bb87d886217e81ab70bc2756e3b47e0519abd36b90f3f60354211c73e4ed1
sha512: 75f338c6c7f6c9e90ed1d3d64c678f79445eb3401d4de4f5c47dc3d75004ded602bf8edd618197ab74b15f802c537901ccd221a0ebfaf6dac5911b8647016417
ssdeep: 1536:aMWBvSI3wc3oAeiCX6tEG7a9GjB4tnYmy1DZeKZe:YSjqCXKgGjYnBy1Fe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T109F3A216B751D810D6685137DEA7D2FA66B6BC4A9F07A20FBA10375F3CB2F046C10A93
sha3_384: 6af323e15f7da1d452003451f91f338b664509c7313e431f72e55bb8b722454decda76d6e7c3df87c8df0338e78e294d
ep_bytes: 68c4124000e8eeffffff000000000000
timestamp: 2012-06-20 04:16:11

Version Info:

Translation: 0x0409 0x04b0
Comments: evangelic appreciatingly
CompanyName: evangelic appreciatingly
FileDescription: evangelic appreciatingly
LegalCopyright: evangelic appreciatingly
LegalTrademarks: evangelic appreciatingly
ProductName: evangelic appreciatingly
FileVersion: 2.04
ProductVersion: 2.04
InternalName: augunddpnh
OriginalFilename: augunddpnh.exe

Worm:Win32/Vobfus.FQ also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lCqw
MicroWorld-eScanWin32.Worm.VB.OAE
FireEyeGeneric.mg.0fe2a5a48de2760a
CAT-QuickHealWorm.WbnaMF.S18680737
SkyhighBehavesLike.Win32.VBObfus.ct
McAfeeVBObfus.ek
MalwarebytesGeneric.Worm.AutoRun.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
AlibabaWorm:Win32/Vobfus.d50effb2
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.48de27
BitDefenderThetaGen:NN.ZevbaF.36802.km0@a8Infoii
VirITTrojan.Win32.VB.E
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.AWX
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMDX
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.WBNA.ipa
BitDefenderWin32.Worm.VB.OAE
NANO-AntivirusTrojan.Win32.Vobfus.cnwqsp
SUPERAntiSpywareTrojan.Agent/Gen-Vban
AvastWin32:VB-ADDH [Trj]
TencentWorm.Win32.Vobfus.n
TACHYONWorm/W32.WBNA.163840.B
EmsisoftWin32.Worm.VB.OAE (B)
BaiduWin32.Worm.VB.pm
F-SecureTrojan.TR/Rogue.kdj.6
DrWebWin32.HLLW.Autoruner1.17570
VIPREWin32.Worm.VB.OAE
TrendMicroWORM_VOBFUS.SMDX
Trapminemalicious.high.ml.score
SophosMal/Vobfus-I
IkarusWorm.Win32.Vobfus
JiangminWorm.WBNA.lepw
GoogleDetected
AviraTR/Rogue.kdj.6
VaristW32/Vobfus.AQ.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.997
MicrosoftWorm:Win32/Vobfus.FQ
XcitiumTrojWare.Win32.AutoRun.ANT@4mtxpu
ArcabitWin32.Worm.VB.OAE
ZoneAlarmWorm.Win32.WBNA.ipa
GDataWin32.Worm.VB.OAE
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.WBNA.R28275
VBA32TScope.Trojan.VB
ALYacWin32.Worm.VB.OAE
MAXmalware (ai score=88)
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
RisingWorm.Autorun!1.DA89 (CLASSIC)
YandexTrojan.GenAsa!9jsV86g+4QE
SentinelOneStatic AI – Malicious PE
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-ADDH [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm:Win32/Vobfus.FQ?

Worm:Win32/Vobfus.FQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment