Worm

About “Worm:Win32/Vobfus.HJ” infection

Malware Removal

The Worm:Win32/Vobfus.HJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.HJ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm:Win32/Vobfus.HJ?


File Info:

name: 1C949038FB0318A1AB94.mlw
path: /opt/CAPEv2/storage/binaries/50f39a62d65fc5ed5ff20081cac74076a1e7545c3c477d15384a89be753407c8
crc32: 07C51745
md5: 1c949038fb0318a1ab948ba256783f9b
sha1: 79ba72ceda3555b3a37b9c3e9548ebd78e2da9ae
sha256: 50f39a62d65fc5ed5ff20081cac74076a1e7545c3c477d15384a89be753407c8
sha512: 19409814c98e62a98dfbba323c6698ed44613846b1d2cafe609feae7ef2e3a52611a47da0b3d9ef85f436d62731d5d21d3515bcbb716f76c988155d81c819c5e
ssdeep: 3072:LKh0FfeKiGLOlx6ktpl/umGZPvX8T0wAt72FREQC2m2F:LKhuznOlx6kt/q5zwAtbvo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C3F3C9246A80EA3DD455CAF4394F8390807AEE3A21EBAE07F7E1279472F1D579364353
sha3_384: 4a60a3bf8270cb90782725e58803af6506f562abe66a8cb32b29910f320dc367b3c457b4c2c9baeb72e7f1b6f8532d47
ep_bytes: 687c3d4000e8eeffffff000000000000
timestamp: 2012-08-31 05:33:09

Version Info:

Translation: 0x0409 0x04b0
ProductName: Canoncito
FileVersion: 9.98
ProductVersion: 9.98
InternalName: apocentric
OriginalFilename: apocentric.exe

Worm:Win32/Vobfus.HJ also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.950
FireEyeGeneric.mg.1c949038fb0318a1
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeGenDownloader.rv
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Barys.950
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
BaiduWin32.Worm.Pronny.d
VirITTrojan.Win32.Generic.BHEH
SymantecW32.Changeup!gen35
tehtrisGeneric.Malware
ESET-NOD32Win32/Pronny.DH
APEXMalicious
AvastWin32:VB-AEIS [Trj]
ClamAVWin.Packer.VBCrypt-5731517-0
KasperskyWorm.Win32.Vobfus.erms
BitDefenderGen:Variant.Barys.950
NANO-AntivirusTrojan.Win32.Jorik2.juqwtb
TencentWorm.Win32.Vobfus.q
EmsisoftGen:Variant.Barys.950 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebWorm.Siggen.8284
TrendMicroWORM_VOBFUS.SMIV
Trapminemalicious.high.ml.score
SophosW32/VBObfus-H
IkarusWorm.Win32.Vobfus
MAXmalware (ai score=88)
JiangminWorm.Vobfus.arrh
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Vobfus.BE.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus.HJ
XcitiumWorm.Win32.Pronny.ABQ@4puwz1
ArcabitTrojan.Barys.950
ViRobotWorm.Win32.A.WBNA.172032.AD
ZoneAlarmWorm.Win32.Vobfus.erms
GDataWin32.Trojan.VB.LW
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Menti.R36838
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36804.km0@aiKJaSki
ALYacGen:Variant.Barys.950
TACHYONTrojan/W32.VB-Jorik.172032
VBA32Malware-Cryptor.VB.gen
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMIV
RisingTrojan.VB!1.99F7 (CLASSIC)
YandexTrojan.GenAsa!kNfUA/hFuC4
SentinelOneStatic AI – Malicious PE
FortinetW32/VBKrypt.CA!tr
AVGWin32:VB-AEIS [Trj]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.dbbaead8

How to remove Worm:Win32/Vobfus.HJ?

Worm:Win32/Vobfus.HJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment