Worm

About “Worm:Win32/Vobfus.IY” infection

Malware Removal

The Worm:Win32/Vobfus.IY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.IY virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Vobfus.IY?


File Info:

name: E6BA58584896A871BE1A.mlw
path: /opt/CAPEv2/storage/binaries/49bfdecd4887e5f7bfd1d15676eea4a4b5c382849cdc1556b5c24fe227b8fa1b
crc32: 1D8B273E
md5: e6ba58584896a871be1a09f3e868e6cf
sha1: 04e3306c3db668f79741588b671de1f6d2bcbf7c
sha256: 49bfdecd4887e5f7bfd1d15676eea4a4b5c382849cdc1556b5c24fe227b8fa1b
sha512: 941461188d8cd645af1b63c2669c316322344d45665b579707f970024b534af107986587a8acb5cb721fc3348ec6abacd3e603846ea507a633cdd357c1a6f8a9
ssdeep: 3072:r17xYpWufuouQSamFi5eLb532qRgzqRe/aT4E1KZnBmaOtDvJRZ8Ng0ykd7XsjP/:r17xPb532qRmqRe/aT4EYDmaOtNRKNA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DE64191673A0FA2AD5218BF02AAA43B4517EEC3115D1A907F7803F1E77B2E975236713
sha3_384: cb7d0b8761570f77ae29d49670bd494785fab1309668992ad2ed96431e21f6c5ab8acc975572e9b902aaa1f0297be423
ep_bytes: 6864434000e8eeffffff000068000000
timestamp: 2012-10-04 19:27:38

Version Info:

Translation: 0x0409 0x04b0
ProductName: ricksha
FileVersion: 8.42
ProductVersion: 8.42
InternalName: incettero
OriginalFilename: incettero.exe

Worm:Win32/Vobfus.IY also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.431239
FireEyeGeneric.mg.e6ba58584896a871
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.fm
McAfeeGenDownloader.rv
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Barys.431239
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.84896a
BitDefenderThetaGen:NN.ZevbaF.36802.tm1@auZqqini
VirITTrojan.Win32.SHeur4.AQUQ
SymantecW32.Changeup
ESET-NOD32Win32/Pronny.FA
APEXMalicious
AvastWin32:VB-AEQD [Trj]
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.scu
BitDefenderGen:Variant.Barys.431239
NANO-AntivirusTrojan.Win32.WBNA.csfhhl
TencentMalware.Win32.Gencirc.10b3205d
SophosMal/SillyFDC-W
BaiduWin32.Worm.Pronny.d
F-SecureTrojan.TR/Symmi.2336989
DrWebWin32.HLLW.Autoruner1.27186
TrendMicroWORM_VOBFUS.SMAS
EmsisoftGen:Variant.Barys.431239 (B)
SentinelOneStatic AI – Malicious PE
JiangminWorm/WBNA.diik
ALYacGen:Variant.Barys.431239
VaristW32/VB.HE.gen!Eldorado
AviraTR/Symmi.2336989
MAXmalware (ai score=80)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.999
MicrosoftWorm:Win32/Vobfus.IY
XcitiumWorm.Win32.VB.PJT@4r48sc
ArcabitTrojan.Barys.D69487
ViRobotWorm.Win32.A.Vobfus.305927
ZoneAlarmWorm.Win32.Vobfus.scu
GDataWin32.Worm.Vobfus.MIWMCT
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Vobfus.R38791
VBA32Malware-Cryptor.VB.gen
GoogleDetected
TACHYONWorm/W32.Vobfus.323638
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMAS
RisingWorm.Pronny!8.2E9 (TFE:3:1kmOeqQQlkH)
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.CA!tr
AVGWin32:VB-AEQD [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudWorm:Win/Vobfus.16fb5ccc

How to remove Worm:Win32/Vobfus.IY?

Worm:Win32/Vobfus.IY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment