Worm

Worm:Win32/Vobfus.FW removal instruction

Malware Removal

The Worm:Win32/Vobfus.FW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.FW virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Vobfus.FW?


File Info:

name: B179279A8BF44BC5483B.mlw
path: /opt/CAPEv2/storage/binaries/757a4c770f7c703f211c6df4d4c7ac462df86a3874cb629f1535df855ebedbd5
crc32: 4D2081EA
md5: b179279a8bf44bc5483b0bfbaa8199a3
sha1: ad52abf7195da244637e3f07c911565e14bb8a3f
sha256: 757a4c770f7c703f211c6df4d4c7ac462df86a3874cb629f1535df855ebedbd5
sha512: ffe0c8eb6be8cff9fe7a211d689e06917b00240ef19b5ff69259d39a127f294ccb0e0ae0b8c676d3a011ade50fd267001996adfe0d429dc3a27b29aaf68422cf
ssdeep: 768:s8b6o5TatanURLQ/JD60XDeVtA5YxmHwWW2iYf/ce2NZQcy8+gxdCwaTDNmDIBTX:sGWUIQ/JDHKa5LJW6/Z2NZQKvdmNmS/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15993D636B20AA05AE859777C2357858715B3A85D1F0B214B6328BF7F5C3AF10892CB77
sha3_384: afc7ef05a12cc960017cf53d2f9cd2ca73438402f86679f48a4f7e3d49ec7148c3fd7b2963a51e5a565b842a893f3804
ep_bytes: 6864124000e8eeffffff000000000000
timestamp: 2012-07-05 18:27:01

Version Info:

Translation: 0x0409 0x04b0
Comments: serapic
CompanyName: serapic
FileDescription: serapic
LegalCopyright: serapic
LegalTrademarks: serapic
ProductName: serapic
FileVersion: 0.27
ProductVersion: 0.27
InternalName: Accreditation
OriginalFilename: Accreditation.exe

Worm:Win32/Vobfus.FW also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner1.18501
MicroWorld-eScanTrojan.GenericKDZ.95770
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.mm
McAfeeZeroAccess.in
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.7195da
BitDefenderThetaGen:NN.ZevbaF.36680.fm0@aCVljrli
VirITWorm.Win32.VB.JX
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.AXK
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.WBNA.naf
BitDefenderTrojan.GenericKDZ.95770
NANO-AntivirusTrojan.Win32.WBNA.crkzkq
SUPERAntiSpywareTrojan.Agent/Gen-Remnat
AvastWin32:VB-ADPU [Trj]
TencentWorm.Win32.WBNA.hf
EmsisoftTrojan.GenericKDZ.95770 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
BaiduWin32.Worm.VB.ax
VIPRETrojan.GenericKDZ.95770
TrendMicroWORM_VOBFUS.SMPI
SophosMal/VBObfus-B
IkarusTrojan.Patched
GDataTrojan.GenericKDZ.95770
JiangminTrojan/Vbobf.b
WebrootW32.Obfuscated.Gen
VaristW32/Vobfus.AT.gen!Eldorado
AviraTR/Patched.Ren.Gen
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Generic.D1761A
ZoneAlarmWorm.Win32.WBNA.naf
MicrosoftWorm:Win32/Vobfus.FW
GoogleDetected
AhnLab-V3Worm/Win32.WBNA.R29524
Acronissuspicious
ALYacTrojan.GenericKDZ.95770
TACHYONWorm/W32.WBNA.90112
VBA32Worm.WBNA
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMPI
RisingWorm.AutoRun!1.E3A5 (CLASSIC)
YandexTrojan.GenAsa!z+TT8C5M2SU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-ADPU [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm:Win32/Vobfus.FW?

Worm:Win32/Vobfus.FW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment