Worm

Worm:Win32/Vobfus.IK malicious file

Malware Removal

The Worm:Win32/Vobfus.IK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.IK virus can do?

  • Executable code extraction
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Worm:Win32/Vobfus.IK?


File Info:

crc32: 342DC616
md5: dd06feeaa5bf2cb9f5170921260ace23
name: DD06FEEAA5BF2CB9F5170921260ACE23.mlw
sha1: dbf9b3429e0ed6b19e29e40c54bc225a9723b7a3
sha256: 1e0aa97aba92ed8b74437683bebf93a7c4ed773151f3f3554a031f09117db235
sha512: 801a7fc76f42ecf8561a1f69400888fd94f2b87d217e7fd5a9f7e506418b24e8c2429dbabfc939002ccc84b7f97c3baf804dd794c43a67bb2b2a9740573e9d03
ssdeep: 1536:dQXuJNyDBeZjhtFgGjtXDTto2D9uCLBCPr8/NL44PerVCI8kIi/2O:6eJNAeZj/FgoTq2prJO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 5.03
InternalName: Jdavie
FileVersion: 5.03
OriginalFilename: Jdavie.exe
ProductName: Coltivare

Worm:Win32/Vobfus.IK also known as:

BkavW32.AIDetect.malware2
K7AntiVirusEmailWorm ( 0054d10f1 )
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner1.26616
CynetMalicious (score: 100)
CAT-QuickHealWorm.VobfusMF.S18680852
ALYacGen:Variant.Barys.950
CylanceUnsafe
ZillyaWorm.Vobfus.Win32.270193
CrowdStrikewin/malicious_confidence_80% (D)
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.aa5bf2
BaiduWin32.Worm.Pronny.ew
CyrenW32/VB.HD.gen!Eldorado
SymantecW32.Changeup!gen20
ESET-NOD32Win32/Pronny.FQ
APEXMalicious
AvastWin32:VB-AEOA [Trj]
ClamAVWin.Trojan.VB-1720
KasperskyWorm.Win32.Vobfus.abuh
BitDefenderGen:Variant.Barys.950
NANO-AntivirusTrojan.Win32.Vobfus.bqoefe
ViRobotWorm.Win32.A.Vobfus.118784
MicroWorld-eScanGen:Variant.Barys.950
TencentWorm.Win32.Vobfus.q
Ad-AwareGen:Variant.Barys.950
SophosMal/Generic-R + Mal/SillyFDC-Y
ComodoWorm.Win32.Pronny.ABQ@4puwz1
BitDefenderThetaGen:NN.ZevbaF.34266.hm0@aiTpkUoi
VIPRETrojan.Win32.Vobfus.paa (v)
TrendMicroWORM_VOBFUS.SM00
McAfee-GW-EditionBehavesLike.Win32.Trickbot.cm
FireEyeGeneric.mg.dd06feeaa5bf2cb9
EmsisoftGen:Variant.Barys.950 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Vbobf.b
AviraTR/Downloader.Gen8
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASBOL.5
MicrosoftWorm:Win32/Vobfus.IK
GDataGen:Variant.Barys.950
TACHYONWorm/W32.Vobfus.118784
AhnLab-V3Worm/Win32.Vobfus.R37786
Acronissuspicious
McAfeeGenDownloader.rv
MAXmalware (ai score=100)
VBA32Worm.Vobfus
MalwarebytesMalware.AI.2379666581
PandaGeneric Malware
TrendMicro-HouseCallWORM_VOBFUS.SM00
RisingWorm.VobfusEx!1.99EB (CLASSIC)
YandexTrojan.GenAsa!fYvWsAMx25M
IkarusWorm.Win32.Vobfus
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-AEOA [Trj]
Paloaltogeneric.ml

How to remove Worm:Win32/Vobfus.IK?

Worm:Win32/Vobfus.IK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment