Worm

Worm:Win32/Vobfus.IP removal guide

Malware Removal

The Worm:Win32/Vobfus.IP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.IP virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Vobfus.IP?


File Info:

name: A74AAF4452408A643416.mlw
path: /opt/CAPEv2/storage/binaries/c6f3df2c84ab5b019e7a4dccb2c187247d6508c0094d1519f0b78a117ca3c042
crc32: EAF35BFA
md5: a74aaf4452408a643416e9f5e03767f9
sha1: da5e06f294d0736746478a99832b8e057800b991
sha256: c6f3df2c84ab5b019e7a4dccb2c187247d6508c0094d1519f0b78a117ca3c042
sha512: 9256ee17ef60060f535e86f309707e613334ab004aeb25aa3c5aea3544a04bbd427b239a4a8b39c222c7b33dc80fc0d7d7250f5f46b7b51580ce4873a83d8fe6
ssdeep: 6144:K5xavQHcZQ2hqU+6ONGn0BbjvwC1SL3HAijW46BqU:K5xavmcZQ2hqU+VNGn0RjvwC1SxjW46X
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1905484112690AE2ED4AC89F0DC9ED390873E6C3251F36837F6D4775976A1C63B92132B
sha3_384: 2938a0f556584f84230f6928063cae61f23145b9bcdcf5bb3f04e190bef0f7211b51681cca88a1ca5e1352313d3340dd
ep_bytes: 689c3f4000e8eeffffff000000000000
timestamp: 2012-09-29 07:44:55

Version Info:

Translation: 0x0409 0x04b0
ProductName: overmost
FileVersion: 9.95
ProductVersion: 9.95
InternalName: Joyant
OriginalFilename: Joyant.exe

Worm:Win32/Vobfus.IP also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Barys.950
CAT-QuickHealWorm.VobfusVMF.S21466219
SkyhighBehavesLike.Win32.GenDownloader.dm
McAfeeGenDownloader.rv
MalwarebytesPronny.Worm.Spreader.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Barys.950
BaiduWin32.Worm.Pronny.d
VirITTrojan.Win32.Generic.BYPW
SymantecW32.Changeup!gen18
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Pronny.ET
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.jod
BitDefenderGen:Variant.Barys.950
NANO-AntivirusTrojan.Win32.Vobfus.ewohwn
AvastWin32:VB-AEOS [Trj]
TencentMalware.Win32.Gencirc.10b70d19
SophosMal/SillyFDC-AC
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner1.26871
VIPREGen:Variant.Barys.950
TrendMicroWORM_VOBFUS.SM00
EmsisoftGen:Variant.Barys.950 (B)
IkarusWorm.Win32.WBNA
JiangminWorm/Vobfus.ayw
WebrootW32.Vobfus
VaristW32/VB.HE.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Pronny.EB@4qtzpj
MicrosoftWorm:Win32/Vobfus.IP
ViRobotWorm.Win32.A.Vobfus.282624
ZoneAlarmWorm.Win32.Vobfus.jod
GDataGen:Variant.Barys.950
GoogleDetected
AhnLab-V3Downloader/Win32.Murlo.R45756
BitDefenderThetaGen:NN.ZevbaF.36680.rm0@a04WpMai
ALYacGen:Variant.Barys.950
VBA32Malware-Cryptor.VB.gen
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM00
RisingWorm.VobfusEx!1.99EB (CLASSIC)
YandexTrojan.GenAsa!6y8gCqqI1e0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.5496659.susgen
FortinetW32/VBKrypt.CA!tr
AVGWin32:VB-AEOS [Trj]
Cybereasonmalicious.294d07
DeepInstinctMALICIOUS

How to remove Worm:Win32/Vobfus.IP?

Worm:Win32/Vobfus.IP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment