Worm

Worm:Win32/Vobfus.FW information

Malware Removal

The Worm:Win32/Vobfus.FW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.FW virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Vobfus.FW?


File Info:

name: 8372D93E03039957A187.mlw
path: /opt/CAPEv2/storage/binaries/4a072f9c7258a1df32014bfa7ae706ccb1c4a846515c8e402fe7e1ffa2a794ba
crc32: AFD43C7F
md5: 8372d93e03039957a1877a55899e8225
sha1: 7ed681db1158797d36fa2c6491329b038c4083b3
sha256: 4a072f9c7258a1df32014bfa7ae706ccb1c4a846515c8e402fe7e1ffa2a794ba
sha512: 715160558eeca6cd8028b668ff006adee1979d95ea6f90595f2c83be3079353206bd3f895c40e0a520d623783f80f8bc53a37c7ea197cae3ea9039e1667cf67c
ssdeep: 768:swb6o56nURLQ/JD60XDeVtA5YxmHwWW2iYf/ce2NZQcy8+gxdCwaTDNmDIBT/kbQ:sq6IQ/JDHKa5LJW6/Z2NZQKvdmNmS/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10093C636B20AA05AF859777C2357858715B3985D2F0B214B6328BF7F5C3AF10892CB67
sha3_384: ee82b53f14ba7fbc2c14fc30e43682c342713f516dff5e93c7db8f6dee4e8accf542e07b106d25fad206666508b61807
ep_bytes: 6864124000e8eeffffff000000000000
timestamp: 2012-07-05 18:27:01

Version Info:

Translation: 0x0409 0x04b0
Comments: serapic
CompanyName: serapic
FileDescription: serapic
LegalCopyright: serapic
LegalTrademarks: serapic
ProductName: serapic
FileVersion: 0.27
ProductVersion: 0.27
InternalName: Accreditation
OriginalFilename: Accreditation.exe

Worm:Win32/Vobfus.FW also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.tnqs
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner1.18501
MicroWorld-eScanTrojan.GenericKDZ.95770
ClamAVWin.Trojan.Changeup-6169544-0
FireEyeGeneric.mg.8372d93e03039957
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.mm
McAfeeZeroAccess.in
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
AlibabaWorm:Win32/Vobfus.ef999381
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.b11587
BitDefenderThetaGen:NN.ZevbaF.36744.fm0@aCVljrli
VirITWorm.Win32.VB.JX
SymantecW32.Changeup
ESET-NOD32Win32/AutoRun.VB.AXK
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.WBNA.naf
BitDefenderTrojan.GenericKDZ.95770
NANO-AntivirusTrojan.Win32.WBNA.crkzkq
SUPERAntiSpywareTrojan.Agent/Gen-Remnat
AvastWin32:VB-ADPU [Trj]
TencentWorm.Win32.WBNA.hf
TACHYONWorm/W32.WBNA.90112
EmsisoftTrojan.GenericKDZ.95770 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
BaiduWin32.Worm.VB.ax
VIPRETrojan.GenericKDZ.95770
TrendMicroWORM_VOBFUS.SMPI
SophosMal/VBObfus-B
IkarusTrojan.Patched
GDataWin32.Trojan.PSE.709C4R
JiangminTrojan/Vbobf.b
WebrootW32.Obfuscated.Gen
GoogleDetected
AviraTR/Patched.Ren.Gen
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.999
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Generic.D1761A
ZoneAlarmWorm.Win32.WBNA.naf
MicrosoftWorm:Win32/Vobfus.FW
VaristW32/Vobfus.AT.gen!Eldorado
AhnLab-V3Worm/Win32.WBNA.R29524
Acronissuspicious
VBA32Worm.WBNA
ALYacTrojan.GenericKDZ.95770
MAXmalware (ai score=82)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMPI
RisingWorm.AutoRun!1.E3A5 (CLASSIC)
YandexTrojan.GenAsa!z+TT8C5M2SU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-ADPU [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Vobfus.FW?

Worm:Win32/Vobfus.FW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment