Worm

Worm:Win32/Vobfus.GS removal

Malware Removal

The Worm:Win32/Vobfus.GS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.GS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Vobfus.GS?


File Info:

name: 18CD241892D4B7EE125E.mlw
path: /opt/CAPEv2/storage/binaries/2fc66d997fcc4147ea6a7275ca050360b10e46f6ad46683b60dc4084ceee543e
crc32: 81E3D224
md5: 18cd241892d4b7ee125e70cfe7d2e71a
sha1: f5249c16c0cf7acefb58e4c2a02757ddef6f27a5
sha256: 2fc66d997fcc4147ea6a7275ca050360b10e46f6ad46683b60dc4084ceee543e
sha512: b78e7fed5f49cc2d9cfcc2ee7aecea12ae4caea95cb47315c2ff66b921870621cc8053464a47392b1e5125b1aa320bc72d326b9f6ebf2dacf7b5611d606b778b
ssdeep: 3072:koHc/jEfW+zx3ad1bCUkZArSnXBUlyiaCeXWnUeg:8bMV3ad1bCUkZArSnXBUlyiaCIh5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E5D3922BBF9E9491E50911386EF3C7F51666AC1A7E07510B6B143B6EE9B3F001C5CA23
sha3_384: 38589e4cedca4c5ce52a53ee1d4919cfe8feda6bc6fe3949ef21f8d9367a480baec529cfbd4af29301d39dee2f9ee5e4
ep_bytes: 68c4124000e8eeffffff000000000000
timestamp: 2012-08-10 05:07:40

Version Info:

Translation: 0x0409 0x04b0
Comments: Prehydration misapprehensively Bushrope
CompanyName: Prehydration misapprehensively Bushrope
FileDescription: Prehydration misapprehensively Bushrope
LegalCopyright: Prehydration misapprehensively Bushrope
LegalTrademarks: Prehydration misapprehensively Bushrope
ProductName: Prehydration misapprehensively Bushrope
FileVersion: 7.92
ProductVersion: 7.92
InternalName: cactoid
OriginalFilename: cactoid.exe

Worm:Win32/Vobfus.GS also known as:

MicroWorld-eScanGen:Heur.VB.Agent.3
FireEyeGeneric.mg.18cd241892d4b7ee
CAT-QuickHealTrojan.Beebone.D
McAfeeVBObfus.ek
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Heur.VB.Agent.3
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.892d4b
VirITWorm.Win32.X-Autorun.BKSE
CyrenW32/VB.HC.gen!Eldorado
SymantecW32.Changeup!gen20
Elasticmalicious (high confidence)
ESET-NOD32Win32/Pronny.CG
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyTrojan.Win32.Jorik.Vobfus.fcga
BitDefenderGen:Heur.VB.Agent.3
NANO-AntivirusTrojan.Win32.Autoruner1.cmxqir
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VBCrypt-BJA [Trj]
TencentTrojan.Win32.Vobfus.hbs
TACHYONTrojan/W32.VB-Jorik.135168
SophosMal/SillyFDC-Y
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner1.24808
TrendMicroWORM_VOBFUS.SM01
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.high.ml.score
EmsisoftGen:Heur.VB.Agent.3 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.VB.Agent.3
JiangminTrojan/Vbobf.b
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.Pronny.CG@4q65me
ArcabitTrojan.VB.Agent.3
ZoneAlarmTrojan.Win32.Jorik.Vobfus.fcga
MicrosoftWorm:Win32/Vobfus.GS
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R32692
BitDefenderThetaGen:NN.ZevbaF.36250.im0@aKkbz6li
ALYacGen:Heur.VB.Agent.3
MAXmalware (ai score=82)
VBA32Trojan.Vobfus
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM01
RisingWorm.Vobfus!1.99D6 (CLASSIC)
YandexTrojan.GenAsa!y9Ragz8q/QE
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VBCrypt-BJA [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Vobfus.GS?

Worm:Win32/Vobfus.GS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment