Worm

Worm:Win32/Vobfus.HZ (file analysis)

Malware Removal

The Worm:Win32/Vobfus.HZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.HZ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Vobfus.HZ?


File Info:

name: 3092C616D98A34C616DD.mlw
path: /opt/CAPEv2/storage/binaries/6a0f8a0ee8f8b8b0563241abd23a2e1be3d0b4f413355ae290fd71f423b05919
crc32: 7709A3E0
md5: 3092c616d98a34c616dd536e589c9550
sha1: ff81adc36fa21e1ec2ae9b8602ef95b46549faf5
sha256: 6a0f8a0ee8f8b8b0563241abd23a2e1be3d0b4f413355ae290fd71f423b05919
sha512: c6f95057dd48cf7bcc426620518f04342f7b7f0401d4fcf88ad4c4d15d0b27317320b5c51a616edbcd2badbfd8f37837b71b2068fa1689bf84ad478a52b30ce0
ssdeep: 3072:EiPyY93+BEX8F+7+w3wrOwo9aDZQNfEq02wfG:EiPyY1+p0fZH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DF04293BB748A8A5CF9923352AEBC3F6166378194F0B4547360437AE5D66F440C6CB2B
sha3_384: 75daf9d6c48b522a6b8b82b35174acc20ec18d8b5eb1c1d0e1fbc53617e6a1ad478eb522264fea3512f3ac8e47dbb789
ep_bytes: 68ac134000e8f0ffffff000000000000
timestamp: 2012-09-18 07:09:14

Version Info:

Translation: 0x0409 0x04b0
ProductName: Dingo
FileVersion: 7.35
ProductVersion: 7.35
InternalName: adombraste
OriginalFilename: adombraste.exe

Worm:Win32/Vobfus.HZ also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.5177
FireEyeGeneric.mg.3092c616d98a34c6
CAT-QuickHealWorm.VobfusMF.S19994096
SkyhighBehavesLike.Win32.GenDownloader.cm
McAfeeGenDownloader.rv
MalwarebytesVBObfus.Worm.Spreader.DDS
ZillyaWorm.Vobfus.Win32.1525599
SangforSuspicious.Win32.Save.vb
AlibabaWorm:Win32/Vobfus.b0fae496
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderThetaGen:NN.ZevbaF.36802.lm0@aummNIji
VirITTrojan.Win32.Zyx.NY
SymantecW32.Changeup!gen20
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/VBObfus.BR
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.bfub
BitDefenderGen:Variant.Symmi.5177
NANO-AntivirusTrojan.Win32.Jorik.covkjo
AvastWin32:VBCrypt-BXH [Drp]
TencentWorm.Win32.Vobfus.bb
TACHYONTrojan/W32.VB-Jorik.188416.E
SophosMal/SillyFDC-Y
F-SecureTrojan.TR/Dropper.VB.Gen5
DrWebWin32.HLLW.Autoruner1.26365
VIPREGen:Variant.Symmi.5177
TrendMicroWORM_VOBFUS.SMIV
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Symmi.5177 (B)
IkarusTrojan.Win32.Jorik
JiangminTrojan.Jorik.bch
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Dropper.VB.Gen5
VaristW32/Vobfus.AQ.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.986
MicrosoftWorm:Win32/Vobfus.HZ
XcitiumTrojWare.Win32.Pronny.EE@4qvpy8
ArcabitTrojan.Symmi.D1439
ZoneAlarmWorm.Win32.Vobfus.bfub
GDataWin32.Trojan.VB.QT
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Vobfus.R36953
VBA32Trojan.Vobfus
ALYacGen:Variant.Symmi.5177
MAXmalware (ai score=86)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMIV
RisingDownloader.Beebone!1.9D26 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.4565004.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VBCrypt-BXH [Drp]
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:Win/Vbobfus.657a626f

How to remove Worm:Win32/Vobfus.HZ?

Worm:Win32/Vobfus.HZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment