Worm

Worm:Win32/Vobfus.IW information

Malware Removal

The Worm:Win32/Vobfus.IW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.IW virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm:Win32/Vobfus.IW?


File Info:

name: 6D14E7E83C5160A2CFDD.mlw
path: /opt/CAPEv2/storage/binaries/1da1b2050235c44fa696f363108e78170df3b1e89b76ed0afbb942966b458dc2
crc32: 29DAACB5
md5: 6d14e7e83c5160a2cfddafaa795a444c
sha1: d835bc611dea340e6f7b02abd64aadbe39be6c0e
sha256: 1da1b2050235c44fa696f363108e78170df3b1e89b76ed0afbb942966b458dc2
sha512: 7ab24ff1ae0a7af434f766cf820fe7a072fcdd3e9f0055ddcd6b99fd6cbe9bff9590fc5e8ae3c648bd1e75d9f2eebe6dcf00adae9d5742a0e499924f40cd9d45
ssdeep: 1536:nMUzh9PWe+nBaRucnRWG1idIvf1xjij+p4jlS2fbwE7h4HVQJte:rieaBajWG1idCQN+Ce
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T100B3D72DBA06C091CA442531EEE7CBED16BA7C169F4B6107BA14372F2C76F140D6CA67
sha3_384: 5ec63ace7f823c48347eac0e8d40dc31ca59c70d54fcabce24c2ed4914776d512edde5024562f3e4944189fa56ed7b44
ep_bytes: 6880134000e8f0ffffff000000000000
timestamp: 2012-10-02 19:54:12

Version Info:

Translation: 0x0409 0x04b0
ProductName: Pricelessness
FileVersion: 1.39
ProductVersion: 1.39
InternalName: Polypragmonic
OriginalFilename: Polypragmonic.exe

Worm:Win32/Vobfus.IW also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.2430
ClamAVWin.Trojan.VB-1721
FireEyeGeneric.mg.6d14e7e83c5160a2
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.GenDownloader.cm
McAfeeGenDownloader.rv
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.11dea3
ArcabitTrojan.Symmi.D97E
VirITTrojan.Win32.Generic.JEC
SymantecW32.Changeup!gen20
ESET-NOD32Win32/Pronny.EY
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.nzp
BitDefenderGen:Variant.Symmi.2430
NANO-AntivirusTrojan.Win32.Vobfus.coonik
AvastWin32:VB-AEPW [Trj]
TencentWorm.Win32.Vobfus.q
EmsisoftGen:Variant.Symmi.2430 (B)
F-SecureTrojan.TR/Downloader.Gen8
DrWebWin32.HLLW.Autoruner1.27056
VIPREGen:Variant.Symmi.2430
TrendMicroWORM_VOBFUS.SM02
SophosMal/SillyFDC-Y
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Vbobf.b
WebrootW32.Worm.Gen
GoogleDetected
AviraTR/Downloader.Gen8
MAXmalware (ai score=80)
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.ABQ@4puwz1
MicrosoftWorm:Win32/Vobfus.IW
ViRobotWorm.Win32.A.Vobfus.110592
ZoneAlarmWorm.Win32.Vobfus.nzp
GDataGen:Variant.Symmi.2430
VaristW32/VB.HE.gen!Eldorado
AhnLab-V3Worm/Win32.Vobfus.R38611
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36680.gm0@amxJ@oni
ALYacGen:Variant.Symmi.2430
TACHYONWorm/W32.Vobfus.110592
VBA32Worm.Vobfus
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM02
RisingMalware.FakeFolder/ICON!1.6AC4 (CLASSIC)
YandexTrojan.GenAsa!1fFuGdmJbq0
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-AEPW [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm:Win32/Vobfus.IW?

Worm:Win32/Vobfus.IW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment