Worm

Worm:Win32/Vobfus.IV malicious file

Malware Removal

The Worm:Win32/Vobfus.IV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.IV virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Vobfus.IV?


File Info:

name: 77882811A278CC95BD7E.mlw
path: /opt/CAPEv2/storage/binaries/7f04140b2901c7a00f62a797106b99692cfbf07c386f06bbec0274a61088ea9a
crc32: 933B9307
md5: 77882811a278cc95bd7e65ccfce2b1ff
sha1: c90a6fd994c9b79a04dc702f8b74b74b3b45d3a6
sha256: 7f04140b2901c7a00f62a797106b99692cfbf07c386f06bbec0274a61088ea9a
sha512: dd1f49a7319436606d0462ddd1883d7aafde3db61e987f0e6579f9d48a00a4a3e948c4ab3b7f70ab6b8934474a5ec17722d16632dc01d32b2b4e25616704ac7d
ssdeep: 1536:MGan4ngzp0B8rz6NuRe305Xrud5N9jRMmBUKH7zD87/u+JcBqVbv1BsbhbEle+Ri:iogee4ufubFKVXcBqB1BGSjNX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C0F34A2BB78084A0D99876701AEBC7E96163BC584F0B820B35407BAE2D77F131D6D74B
sha3_384: f639c42847a5c22669bce6bb09031d45ae09d4148ba11ce029eba5d621247dfd414bd1f97e940e74c0b8e65b43b580c7
ep_bytes: 6898134000e8eeffffff000058000000
timestamp: 2012-10-03 18:18:25

Version Info:

Translation: 0x0409 0x04b0
ProductName: pharyngitic
FileVersion: 4.32
ProductVersion: 4.32
InternalName: Proletariatism
OriginalFilename: Proletariatism.exe

Worm:Win32/Vobfus.IV also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.3150
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.cm
ALYacGen:Variant.Symmi.3150
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Symmi.DC4E
BaiduWin32.Worm.VB.mk
VirITWorm.Win32.VB.NF
SymantecW32.Changeup!gen20
ESET-NOD32Win32/AutoRun.VB.AZA
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMAW
ClamAVWin.Trojan.VB-1553
KasperskyWorm.Win32.Vobfus.pjt
BitDefenderGen:Variant.Symmi.3150
NANO-AntivirusTrojan.Win32.Vobfus.covkfi
AvastWin32:VBCrypt-BNX [Trj]
TencentWorm.Win32.Vobfus.haj
TACHYONWorm/W32.VB-Vobfus.159744.E
EmsisoftGen:Variant.Symmi.3150 (B)
GoogleDetected
F-SecureTrojan.TR/Dropper.VB.Gen5
DrWebWin32.HLLW.Autoruner1.27038
VIPREGen:Variant.Symmi.3150
TrendMicroWORM_VOBFUS.SMAW
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.77882811a278cc95
SophosMal/SillyFDC-Y
SentinelOneStatic AI – Suspicious PE
JiangminWorm.Vobfus.qaac
VaristW32/VB.HE.gen!Eldorado
AviraTR/Dropper.VB.Gen5
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.996
XcitiumWorm.Win32.VB.PJT@4r48sc
MicrosoftWorm:Win32/Vobfus.IV
ViRobotWorm.Win32.A.Vobfus.159744.A
ZoneAlarmWorm.Win32.Vobfus.pjt
GDataGen:Variant.Symmi.3150
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Vobfus.R38791
Acronissuspicious
McAfeeGenDownloader.rv
MAXmalware (ai score=87)
VBA32Worm.Vobfus
Cylanceunsafe
PandaTrj/Genetic.gen
RisingWorm.Vobfus!8.10E (TFE:3:VBKsy9ybABB)
YandexTrojan.GenAsa!+C5PXvT4TFY
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.4627298.susgen
FortinetW32/VBObfus.AU!tr
BitDefenderThetaGen:NN.ZevbaF.36802.jm0@aqpO2hpi
AVGWin32:VBCrypt-BNX [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:Win/Symmi.de26d285

How to remove Worm:Win32/Vobfus.IV?

Worm:Win32/Vobfus.IV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment