Worm

Worm:Win32/Vobfus.KV malicious file

Malware Removal

The Worm:Win32/Vobfus.KV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.KV virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Vobfus.KV?


File Info:

name: 2C6C0454E74154BD193D.mlw
path: /opt/CAPEv2/storage/binaries/cdb3500ea7be12b88fe7797f6c6faa970881b06817f33b9f9c209d0f1534d8d5
crc32: 48DD4508
md5: 2c6c0454e74154bd193d427ffe743371
sha1: b64a5333dc57544f9cb77a58392aa04a00c9605f
sha256: cdb3500ea7be12b88fe7797f6c6faa970881b06817f33b9f9c209d0f1534d8d5
sha512: 8b192420df81222a96143626797382a057b127201c96132e092da2ee848644cddc4930aef71c5460b7b9e9367ff2c0809cc115272af8af66d64c930a5f0975dd
ssdeep: 1536:LakkbuIXVHKTU097h91gKaSFlc4IE3IezPoVtTqtFyUoHnkHUS65Bciufm9x3l:ukkbugKTU0brMmWAojqbdBuLV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T182E3F92B775558CADE04167026F6DAF25AA374698F0752472280772E2DF6F102EACFC3
sha3_384: fec595596520e0622e514965b94623137ad150c88daa87e2318a3c37ce19d960abd49e8249b07a3b77202a8083bac432
ep_bytes: 6898124000e8eeffffff000068000000
timestamp: 2001-03-16 11:08:33

Version Info:

0: [No Data]

Worm:Win32/Vobfus.KV also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cerbu.167481
CAT-QuickHealTrojan.Beebone.D
McAfeeW32/Autorun.worm.aaeh
MalwarebytesVB.Trojan.Generic.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.4e7415
BaiduWin32.Worm.VB.i
VirITTrojan.Win32.VBCrypt.FAO
CyrenW32/VB.HC.gen!Eldorado
SymantecW32.Changeup
ESET-NOD32a variant of Win32/VB.OFR
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.aigm
BitDefenderGen:Variant.Cerbu.167481
NANO-AntivirusTrojan.Win32.Vobfus.hnknzt
AvastWin32:VB-AEVV [Trj]
TencentWorm.Win32.Vobfus.hm
TACHYONTrojan/W32.VB-Agent.143360.GE
EmsisoftGen:Variant.Cerbu.167481 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner1.29052
VIPREGen:Variant.Cerbu.167481
McAfee-GW-EditionBehavesLike.Win32.VBObfus.ct
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.2c6c0454e74154bd
SophosML/PE-A
IkarusTrojan.Patched
GDataGen:Variant.Cerbu.167481
JiangminWorm/Vobfus.imk
WebrootTrojan.Dropper.Gen
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
ArcabitTrojan.Cerbu.D28E39
ZoneAlarmWorm.Win32.Vobfus.aigm
MicrosoftWorm:Win32/Vobfus.KV
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Jorik.R565916
BitDefenderThetaGen:NN.ZevbaF.36250.imY@auzgf0b
ALYacGen:Variant.Cerbu.167481
MAXmalware (ai score=81)
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaTrj/Genetic.gen
RisingWorm.VobfusEx!1.99E0 (CLASSIC)
YandexTrojan.GenAsa!hl+pMaZdNMQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.ADYA!tr
AVGWin32:VB-AEVV [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm:Win32/Vobfus.KV?

Worm:Win32/Vobfus.KV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment