Worm

About “Worm:Win32/Vobfus.FY” infection

Malware Removal

The Worm:Win32/Vobfus.FY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.FY virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm:Win32/Vobfus.FY?


File Info:

name: BD2DA5CF716E6BA5E15D.mlw
path: /opt/CAPEv2/storage/binaries/d647aa2edc9309cfe3da9313f65c0423016605f94b0f328241d9f309ffcc0267
crc32: E4808852
md5: bd2da5cf716e6ba5e15d7c13d785a9bd
sha1: eb15767bdcafe936dbb6b7689b28b22146859941
sha256: d647aa2edc9309cfe3da9313f65c0423016605f94b0f328241d9f309ffcc0267
sha512: c7c37da49479d034e99f1ffb4ad552ca23f0064a46db0c93ffa0f60f3f04e0a24fbeea288fe12032f85808086293c016e0087ee6bdab94c39d8c8c8b060024e6
ssdeep: 1536:aiEFrOXsgnZ7QaI076EXJ/kMkRWnSRIsMFWFii3JXqkJZXLvDmNmond:QBOFKHNond
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18793D52CB7095067E6556B782367CAC609BB6C1E5F0B604FA7047FAF2C34F840869B67
sha3_384: 541a620c781fe354e0ab64bfb28c8fea2f153baab039789ea019d99f679441937e9f01670447c8849045b03003f357e5
ep_bytes: 6888134000e8eeffffff000000000000
timestamp: 2012-07-04 19:05:32

Version Info:

Translation: 0x0409 0x04b0
Comments: Copriamo
CompanyName: Copriamo
FileDescription: Copriamo
LegalCopyright: Copriamo
LegalTrademarks: Copriamo
ProductName: Copriamo
FileVersion: 8.38
ProductVersion: 8.38
InternalName: Creedsman
OriginalFilename: Creedsman.exe

Worm:Win32/Vobfus.FY also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner1.18425
MicroWorld-eScanGen:Heur.VB.Agent.3
CAT-QuickHealTrojan.Beebone.D
McAfeeGeneric VB.jb
MalwarebytesWorm.Obfuscator
VIPREGen:Heur.VB.Agent.3
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 003c363a1 )
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.f716e6
BitDefenderThetaGen:NN.ZevbaF.36250.fm0@aW0UuLpi
VirITTrojan.Win32.Cryptor.RR
CyrenW32/Vobfus.AX.gen!Eldorado
SymantecW32.Changeup!gen20
tehtrisGeneric.Malware
ESET-NOD32Win32/Pronny.BH
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.ipd
BitDefenderGen:Heur.VB.Agent.3
NANO-AntivirusTrojan.Win32.VB.covkdl
ViRobotWorm.Win32.A.VBNA.94208.EC
AvastWin32:VB-ADPH [Trj]
TencentMalware.Win32.Gencirc.10b2022c
EmsisoftGen:Heur.VB.Agent.3 (B)
F-SecureTrojan.TR/VB.Inject.11598
BaiduWin32.Worm.Pronny.ef
TrendMicroWORM_VOBFUS.SM01
McAfee-GW-EditionBehavesLike.Win32.VBObfus.nm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.bd2da5cf716e6ba5
SophosMal/Kovter-W
IkarusVirus.Win32.Cryptor
GDataGen:Heur.VB.Agent.3
JiangminWorm.Vobfus.ptwg
GoogleDetected
AviraTR/VB.Inject.11598
MAXmalware (ai score=80)
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.VB.Agent.3
SUPERAntiSpywareTrojan.Agent/Gen-VBInject
ZoneAlarmWorm.Win32.Vobfus.ipd
MicrosoftWorm:Win32/Vobfus.FY
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.WBNA.R29524
VBA32TScope.Trojan.VB
ALYacGen:Heur.VB.Agent.3
TACHYONWorm/W32.VB-VBNA.94208.F
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM01
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!Qc4FyiYxk1s
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.4785716.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-ADPH [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm:Win32/Vobfus.FY?

Worm:Win32/Vobfus.FY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment