Worm

Worm:Win32/Vobfus.IJ removal guide

Malware Removal

The Worm:Win32/Vobfus.IJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.IJ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Vobfus.IJ?


File Info:

name: 1721B575BAD7D775118A.mlw
path: /opt/CAPEv2/storage/binaries/ab491a7c9f885e447aac98de05f4a43994e5c702fcf0bb88dbe3a06be420d599
crc32: ED3E0415
md5: 1721b575bad7d775118a019784c1c75d
sha1: c532816992c77fa33ae1cd1f07c481d2650ee429
sha256: ab491a7c9f885e447aac98de05f4a43994e5c702fcf0bb88dbe3a06be420d599
sha512: 1b172dc53e529ba4e82ab3b79f2e2112580dfc81af1e5d216b5dfe9656b899b81c0e908ab5681a9d6c8611f43c57eb93a9e04f53b2e0b940ee8a89fb3bf40093
ssdeep: 1536:t5Q8p+4DBeZUBFTgVjtXZTto1e9uCLBCPr8/NL44PerV5I8kIi/2O:bbp+CeZU7TgdTq1ZrJO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EAC3E63FBA569465E519293029F7C7F616BB6C1A2E0B505B6B0033BA4DB3F000C9DE67
sha3_384: f194f277e04bbbbd3ebc5a098dd14727ed7d7e731e9fecc3f23a2fb8d39d79a3ca90f7c584539c6fb6a36b92ccbe5822
ep_bytes: 689c134000e8eeffffff000000000000
timestamp: 2012-09-25 06:23:42

Version Info:

Translation: 0x0409 0x04b0
ProductName: Coltivare
FileVersion: 5.03
ProductVersion: 5.03
InternalName: Jdavie
OriginalFilename: Jdavie.exe

Worm:Win32/Vobfus.IJ also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.950
FireEyeGeneric.mg.1721b575bad7d775
CAT-QuickHealWorm.VobfusMF.S28101913
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeGenDownloader.rv
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Barys.950
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Barys.950
BaiduWin32.Worm.Pronny.ew
VirITTrojan.Win32.Generic.GIZ
SymantecW32.Changeup!gen20
ESET-NOD32Win32/Pronny.FQ
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.VB-1720
KasperskyWorm.Win32.Vobfus.agxr
BitDefenderGen:Variant.Barys.950
NANO-AntivirusTrojan.Win32.Autoruner.cinaru
AvastWin32:VB-AEOA [Trj]
TencentWorm.Win32.Vobfus.ky
TACHYONWorm/W32.Vobfus.118784
SophosMal/SillyFDC-Y
F-SecureTrojan.TR/Downloader.Gen8
DrWebWin32.HLLW.Autoruner1.26616
TrendMicroWORM_VOBFUS.SM00
EmsisoftGen:Variant.Barys.950 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Vbobf.b
WebrootW32.Malware.Gen
VaristW32/VB.HD.gen!Eldorado
AviraTR/Downloader.Gen8
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.Pronny.ABQ@4puwz1
MicrosoftWorm:Win32/Vobfus.IJ
ViRobotWorm.Win32.A.Vobfus.118784
ZoneAlarmWorm.Win32.Vobfus.agxr
GDataGen:Variant.Barys.950
GoogleDetected
AhnLab-V3Worm/Win32.Vobfus.R37786
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36680.hm0@aeBxWJfi
ALYacGen:Variant.Barys.950
MAXmalware (ai score=84)
VBA32Worm.Vobfus
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM00
RisingWorm.VobfusEx!1.99EB (CLASSIC)
YandexTrojan.GenAsa!fYvWsAMx25M
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.4585128.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-AEOA [Trj]
Cybereasonmalicious.992c77
DeepInstinctMALICIOUS

How to remove Worm:Win32/Vobfus.IJ?

Worm:Win32/Vobfus.IJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment