Worm

Worm:Win32/Vobfus.IX (file analysis)

Malware Removal

The Worm:Win32/Vobfus.IX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.IX virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm:Win32/Vobfus.IX?


File Info:

name: E3E72AA04603B70260A1.mlw
path: /opt/CAPEv2/storage/binaries/3b7f621e63c2d086787654f5402b9885c07d3fa71345236a191545abbc2e6965
crc32: 3DF9C3B1
md5: e3e72aa04603b70260a10f37889aca7c
sha1: 6692baca66d87c7208742d13e97d0a525be2a534
sha256: 3b7f621e63c2d086787654f5402b9885c07d3fa71345236a191545abbc2e6965
sha512: c642233b25247724c4f8c0d8c765ee7a95846c85300a9caea43c7c71ddb0497f4af794afa1956ba1c25f6d87a6d779cbd21bba88f053eac8150ece88040ad1f0
ssdeep: 3072:gyEJ5u3uXu+ho96wDO1kg3QHOtEOfDjNX:B4hmnD0k
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T106244A2BB7949992C659263119A7C7F52663BC698F0B430B26443B6F2C73F930D6834F
sha3_384: ebe4a73252e53c0c2bce90e63da39ae24f18b0b64f1911ce257265930c53ff40c407b63d3f3a243bd47afe02d2fc05d8
ep_bytes: 68b8134000e8f0ffffff000050000000
timestamp: 2012-10-04 07:19:29

Version Info:

Translation: 0x0409 0x04b0
ProductName: Metamorphy
FileVersion: 5.37
ProductVersion: 5.37
InternalName: hazardful
OriginalFilename: hazardful.exe

Worm:Win32/Vobfus.IX also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.3150
FireEyeGeneric.mg.e3e72aa04603b702
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.GenDownloader.dm
McAfeeGenDownloader.rv
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Symmi.3150
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZevbaF.36802.nm0@aC0EOndi
VirITWorm.Win32.VB.KJ
SymantecW32.Changeup!gen20
ESET-NOD32Win32/Pronny.EZ
APEXMalicious
AvastWin32:VB-AEQC [Trj]
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.tss
BitDefenderGen:Variant.Symmi.3150
NANO-AntivirusTrojan.Win32.Vobfus.crkzsi
TencentWorm.Win32.Vobfus.hab
EmsisoftGen:Variant.Symmi.3150 (B)
BaiduWin32.Worm.Pronny.fh
F-SecureTrojan.TR/Downloader.Gen8
DrWebWin32.HLLW.Autoruner1.27094
TrendMicroWORM_VOBFUS.SM02
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-Y
IkarusWorm.Win32.Vobfus
JiangminTrojan/Vbobf.b
GoogleDetected
AviraTR/Downloader.Gen8
MAXmalware (ai score=83)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.990
MicrosoftWorm:Win32/Vobfus.IX
XcitiumWorm.Win32.VB.PJT@4r48sc
ArcabitTrojan.Symmi.DC4E
ViRobotWorm.Win32.A.Vobfus.221184
ZoneAlarmWorm.Win32.Vobfus.tss
GDataWin32.Trojan.PSE.1UDWI8J
VaristW32/VB.HE.gen!Eldorado
AhnLab-V3Worm/Win32.Vobfus.R38791
Acronissuspicious
VBA32Worm.Vobfus
ALYacGen:Variant.Symmi.3150
TACHYONWorm/W32.Vobfus.221184
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM02
RisingWorm.Pronny!1.E3E5 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Diple.EJQE!tr
AVGWin32:VB-AEQC [Trj]
Cybereasonmalicious.04603b
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.e772c8c3

How to remove Worm:Win32/Vobfus.IX?

Worm:Win32/Vobfus.IX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment