Worm

What is “Worm:Win32/Vobfus.HH”?

Malware Removal

The Worm:Win32/Vobfus.HH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.HH virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Vobfus.HH?


File Info:

name: 854A15F8CD0A914E2A9C.mlw
path: /opt/CAPEv2/storage/binaries/a4fb88a7c5806641be76c9f9740aabebee37896b1bba6743e38ecd90234707a8
crc32: 26F21F5E
md5: 854a15f8cd0a914e2a9c4017d7d21987
sha1: 2068978c7451d8a3d88f97eabf2ec87d2dd7e63a
sha256: a4fb88a7c5806641be76c9f9740aabebee37896b1bba6743e38ecd90234707a8
sha512: 28581032366caf9061c4e8ba017fc40f3bfc264c7e9211e5d24be77b7cb8e2830d34203e579738e0da38ad7e54dc3f1bba85985b9465e62ce68d6fbc9560c9fd
ssdeep: 1536:Po9LxOf4BlqPAKixnX+PBcRlouQvSPouXZ6D6Jj5wl+dwCMZUbP7X2YhxYAZxZCq:gPKalqPpU+Pco6ouZ68Kl+dnMZUbxd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T145E30B2BBBA69056E67916302AF3C7F196B7BC3B5B0B411F674432291CB1F140C68B67
sha3_384: f2731cdec09407209ff15e0ca195e6d691d247da84a2f024b26fc668a546e9ad6a36f6c5e898feb7af8ec729dacc5af7
ep_bytes: 68e8124000e8eeffffff000000000000
timestamp: 2012-08-30 02:37:00

Version Info:

Translation: 0x0409 0x04b0
Comments: acquietava ninnyism
CompanyName: acquietava ninnyism
FileDescription: acquietava ninnyism
LegalCopyright: acquietava ninnyism
LegalTrademarks: acquietava ninnyism
ProductName: acquietava ninnyism
FileVersion: 0.79
ProductVersion: 0.79
InternalName: Undonated
OriginalFilename: Undonated.exe

Worm:Win32/Vobfus.HH also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.96469
ClamAVWin.Trojan.VB-1644
CAT-QuickHealWorm.WbnaMF.S18680882
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeGenDownloader.rv
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.c7451d
BaiduWin32.Worm.Vobfus.a
VirITTrojan.Win32.SHeur4.AODM
SymantecW32.Changeup!gen20
ESET-NOD32a variant of Win32/VBObfus.AS
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.WBNA.ipa
BitDefenderTrojan.GenericKDZ.96469
NANO-AntivirusTrojan.Win32.Jorik.cinaxj
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:VB-AEIM [Trj]
RisingWorm.WBNA!8.321 (TFE:3:tAnIcAT5n3S)
EmsisoftTrojan.GenericKDZ.96469 (B)
F-SecureWorm.WORM/Vobfus.M
DrWebWin32.HLLW.Autoruner2.15623
VIPRETrojan.GenericKDZ.96469
TrendMicroWORM_VOBFUS.SM02
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.854a15f8cd0a914e
SophosMal/Kovter-W
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.96469
JiangminTrojan/Vbobf.b
WebrootW32.Worm.M
GoogleDetected
AviraWORM/Vobfus.M
MAXmalware (ai score=82)
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.ABQ@4puwz1
ArcabitTrojan.Generic.D178D5
ZoneAlarmWorm.Win32.WBNA.ipa
MicrosoftWorm:Win32/Vobfus.HH
VaristW32/VB.HD.gen!Eldorado
AhnLab-V3Trojan/Win32.Vobfus.R37686
BitDefenderThetaGen:NN.ZevbaF.36744.jm0@aGtRidni
ALYacTrojan.GenericKDZ.96469
TACHYONWorm/W32.WBNA.151552.C
VBA32Trojan.Vobfus
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallWORM_VOBFUS.SM02
TencentWorm.Win32.Vobfus.q
YandexTrojan.GenAsa!lBwzqoXSEQA
IkarusTrojan-Downloader.Win32.Beebone
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Diple.EJQE!tr
AVGWin32:VB-AEIM [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm:Win32/Vobfus.HH?

Worm:Win32/Vobfus.HH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment