Worm

Should I remove “Worm:Win32/Vobfus.IM”?

Malware Removal

The Worm:Win32/Vobfus.IM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.IM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Vobfus.IM?


File Info:

name: A79E99BDFAF73F6F5BE9.mlw
path: /opt/CAPEv2/storage/binaries/3dd828a233b882df462155e071404b2901a2d4ebcb5ce688254daaefe9139f78
crc32: E2F292FF
md5: a79e99bdfaf73f6f5be95c2c41c7e220
sha1: 4c38d6300785d0b4c02cd0c3f52b7bcecf4c2f4d
sha256: 3dd828a233b882df462155e071404b2901a2d4ebcb5ce688254daaefe9139f78
sha512: f182e8a3800bb6413ab3beb4a4458a1542cfbfae16bd1c9fbb93aa334c870adb7201b695c26baf5d8bf407c038ee5a6475f6b1c370e4c045007f51d3731d9fa5
ssdeep: 1536:bAhvr9fLieh6hC3KwTHlyHcw1rqVjSxakAyBGGcJ5J9r:EhTlWehWwTHlyHBQNSxWJ9r
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BEA3E77E7A469856DA28673466F2C3D601BA7C472B4B414FAA04376A1CF3F140C6CFA7
sha3_384: 00f91553cf8ddc53a264e4abd1007f20239da0024c15104514fb52d8f4ec6d487c9a9e204dfc1ff830ab30145b11ec21
ep_bytes: 6884134000e8eeffffff000000000000
timestamp: 2012-09-27 05:33:34

Version Info:

Translation: 0x0409 0x04b0
ProductName: circondero
FileVersion: 7.65
ProductVersion: 7.65
InternalName: impalpably
OriginalFilename: impalpably.exe

Worm:Win32/Vobfus.IM also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Vobfus.lEck
MicroWorld-eScanGen:Variant.Barys.950
FireEyeGeneric.mg.a79e99bdfaf73f6f
CAT-QuickHealWorm.VobfusMF.S28717827
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeGenDownloader.rv
MalwarebytesGeneric.Malware.AI.DDS
ZillyaWorm.Vobfus.Win32.93394
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Vobfus.29802d08
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Worm.Pronny.da
VirITTrojan.Win32.X-Cryptor.GB
SymantecW32.Changeup!gen20
Elasticmalicious (high confidence)
ESET-NOD32Win32/Pronny.FY
APEXMalicious
ClamAVWin.Trojan.Vobfus-63
KasperskyWorm.Win32.Vobfus.aiib
BitDefenderGen:Variant.Barys.950
NANO-AntivirusTrojan.Win32.Vobfus.covkbl
AvastWin32:VB-AEOI [Trj]
TencentWorm.Win32.Vobfus.q
EmsisoftGen:Variant.Barys.950 (B)
F-SecureTrojan.TR/Downloader.Gen8
DrWebWin32.HLLW.Autoruner1.26769
VIPREGen:Variant.Barys.950
TrendMicroWORM_VOBFUS.SM00
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-Y
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=100)
GDataGen:Variant.Barys.950
JiangminTrojan/Vbobf.b
WebrootW32.Obfuscated.Gen
GoogleDetected
AviraTR/Downloader.Gen8
VaristW32/VB.HE.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
KingsoftWin32.HeurC.KVM007.a
XcitiumWorm.Win32.Pronny.ABQ@4puwz1
ArcabitTrojan.Barys.950
ZoneAlarmWorm.Win32.Vobfus.aiib
MicrosoftWorm:Win32/Vobfus.IM
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Vobfus.R38898
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36744.gm0@aisVh7ji
ALYacGen:Variant.Barys.950
TACHYONWorm/W32.Vobfus.106496
VBA32Worm.Vobfus
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SM00
RisingWorm.VobfusEx!1.99DD (CLOUD)
YandexTrojan.GenAsa!A8EjGzqI3C8
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.ADYA!tr
AVGWin32:VB-AEOI [Trj]
Cybereasonmalicious.00785d
DeepInstinctMALICIOUS

How to remove Worm:Win32/Vobfus.IM?

Worm:Win32/Vobfus.IM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment