Worm

Worm:Win32/Vobfus.GW removal tips

Malware Removal

The Worm:Win32/Vobfus.GW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.GW virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm:Win32/Vobfus.GW?


File Info:

name: 693175952C247ED936DB.mlw
path: /opt/CAPEv2/storage/binaries/fe3a489e7596aea981064056dc15ed472471b1081b34583842cbb81452406c89
crc32: 2DA4266F
md5: 693175952c247ed936db3580f1c23b01
sha1: 5beda0b5109904fa16d2822f070265c548854c8b
sha256: fe3a489e7596aea981064056dc15ed472471b1081b34583842cbb81452406c89
sha512: d25c98d20a840c9346a7aa92a1c6a7cbd1f4f40efbff418725935fa24b828129f45ea65166e9fb5666d4f26ba4547492e01deeb1567a524e2aa15eabda8b472e
ssdeep: 3072:jDGXZEu7o897rl2Y4HpRSQ8nsl8Koay6Vs68:OEulF8HpRpAKoahVsZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C904C53FBE4252A6E51D593526F7CBE01AA73C2D4E4B805B6A44332A2CB2F340C5D657
sha3_384: 983ba3a368f2f2a04040ab1dc874a69ebd1f177e1570ba3bf6f9795e7bade7bb19c9f1504a4cd2378f100823a6cbd91e
ep_bytes: 6868134000e8eeffffff000000000000
timestamp: 2012-08-14 17:46:39

Version Info:

Translation: 0x0409 0x04b0
Comments: Recapitulate mendicity
CompanyName: Recapitulate mendicity
FileDescription: Recapitulate mendicity
LegalCopyright: Recapitulate mendicity
LegalTrademarks: Recapitulate mendicity
ProductName: Recapitulate mendicity
FileVersion: 4.64
ProductVersion: 4.64
InternalName: protodeacon
OriginalFilename: protodeacon.exe

Worm:Win32/Vobfus.GW also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.VB.Agent.3
ClamAVWin.Trojan.VB-1622
CAT-QuickHealTrojan.JorikMF.S28112633
McAfeeGenDownloader.rv
MalwarebytesVBObfus.Worm.Spreader.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.52c247
VirITTrojan.Win32.VB.ALK
CyrenW32/VB.HD.gen!Eldorado
SymantecW32.Changeup
ESET-NOD32a variant of Win32/VBObfus.AC
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Jorik.Vobfus.fcnz
BitDefenderGen:Heur.VB.Agent.3
NANO-AntivirusTrojan.Win32.Jorik.egbjdg
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-AECH [Trj]
TencentTrojan.Win32.Jorik.he
TACHYONTrojan/W32.VB-Jorik.188416.C
SophosMal/Kovter-W
F-SecureWorm.WORM/Vobfus.GW.611
DrWebWin32.HLLW.Autoruner1.24911
VIPREGen:Heur.VB.Agent.3
TrendMicroWORM_VOBFUS.SM02
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.693175952c247ed9
EmsisoftGen:Heur.VB.Agent.3 (B)
IkarusWorm.Win32.Vobfus
GDataWin32.Trojan.PSE.1UMW076
WebrootW32.Worm.Gw
AviraWORM/Vobfus.GW.611
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.ABQ@4puwz1
ArcabitTrojan.VB.Agent.3
ZoneAlarmTrojan.Win32.Jorik.Vobfus.fcnz
MicrosoftWorm:Win32/Vobfus.GW
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R33575
BitDefenderThetaGen:NN.ZevbaF.36196.lm0@aSLaNIpi
ALYacGen:Heur.VB.Agent.3
MAXmalware (ai score=80)
VBA32Trojan.Vobfus
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM02
RisingWorm.VobfusEx!1.99DC (CLASSIC)
YandexTrojan.GenAsa!9l9VOQzYyd8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.4385836.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-AECH [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm:Win32/Vobfus.GW?

Worm:Win32/Vobfus.GW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment