Worm

Should I remove “Worm:Win32/Vobfus.MQ”?

Malware Removal

The Worm:Win32/Vobfus.MQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.MQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Vobfus.MQ?


File Info:

name: 9DBF0759A7488E5AA9F4.mlw
path: /opt/CAPEv2/storage/binaries/0784fe6c8bc7112631dc7bbec1ee1a7b1bf79cf097d45e9c93c79b9f5fff851e
crc32: 8B103744
md5: 9dbf0759a7488e5aa9f41c2c693d8250
sha1: b1f61c8f80f4e10ad1bb68b6c01db5e3e005e981
sha256: 0784fe6c8bc7112631dc7bbec1ee1a7b1bf79cf097d45e9c93c79b9f5fff851e
sha512: 576a4cac4548226ca4186b7c88f8251552b5a3419cf2df2a3695b11988294976835548c3526b68b654ea44611add3cdf3703475d3bcb4f6ba1a6409840efc440
ssdeep: 3072:94e9gmss0FvbVJznCRcz/hVFA9MSs/PLLj+Qm4U3YwgTeA3YE:CjvbfznH7O9G/PLLxU3YwgT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1614418BBFB60A8A6D91922751EF6C7F51563BC594F07810BA204336E2DE3F405D6CA83
sha3_384: 3379cb111d8c4ea67d729fc32913eeb5ba6a2d89239221a9d882a5e17797cf5c368fab19466b1d0230632f0f036d64b9
ep_bytes: 6838124000e8f0ffffff000000000000
timestamp: 2012-12-01 20:53:12

Version Info:

CompanyName: hehzcmuvt
ProductName: xsomdoz
FileVersion: 4.22
ProductVersion: 4.22
InternalName: oclnzxg
OriginalFilename: oclnzxg.exe

Worm:Win32/Vobfus.MQ also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Vobfus.o!c
tehtrisGeneric.Malware
MicroWorld-eScanGeneric.Dacic.1588.303D9736
FireEyeGeneric.mg.9dbf0759a7488e5a
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeW32/Autorun.worm.rd
Cylanceunsafe
ZillyaWorm.WBNA.Win32.1881760
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 005684c41 )
AlibabaWorm:Win32/Vobfus.25532f6f
K7GWTrojan ( 005569741 )
Cybereasonmalicious.9a7488
BitDefenderThetaGen:NN.ZevbaF.36802.rm0@aaVnpifi
VirITTrojan.Win32.VBCrypt.FCE
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Pronny.JI
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMIS
ClamAVWin.Worm.Vobfus-6980126-0
KasperskyWorm.Win32.WBNA.ipa
BitDefenderGeneric.Dacic.1588.303D9736
NANO-AntivirusTrojan.Win32.Vobfus.ccwdgs
AvastWin32:VB-AFFD [Trj]
TencentWorm.Win32.Vobfus.t
TACHYONWorm/W32.WBNA.278528
EmsisoftGeneric.Dacic.1588.303D9736 (B)
BaiduWin32.Worm.Pronny.c
F-SecureWorm.WORM/Vobfus.6659874
DrWebTrojan.DownLoader7.33695
VIPREGeneric.Dacic.1588.303D9736
TrendMicroWORM_VOBFUS.SMIS
Trapminemalicious.high.ml.score
SophosMal/Autorun-AX
IkarusWorm.Win32.Vobfus
JiangminWorm/Vobfus.iqs
GoogleDetected
AviraWORM/Vobfus.6659874
VaristW32/VB.HC.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.997
MicrosoftWorm:Win32/Vobfus.MQ
XcitiumTrojWare.Win32.VBObfus.id@4sbby6
ArcabitGeneric.Dacic.1588.303D9736
ViRobotWorm.Win32.A.Vobfus.278528.GF
ZoneAlarmWorm.Win32.WBNA.ipa
GDataGeneric.Dacic.1588.303D9736
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Vobfus.R44930
VBA32Worm.Vobfus
ALYacGeneric.Dacic.1588.303D9736
MAXmalware (ai score=100)
MalwarebytesPronny.Worm.Spreader.DDS
PandaW32/Vobfus.gen.worm
RisingWorm.Vobfus!8.10E (TFE:3:wla9k1w1izK)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.5496659.susgen
FortinetW32/WBNA.IPA!worm
AVGWin32:VB-AFFD [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudWorm:Win/Pronny.JI

How to remove Worm:Win32/Vobfus.MQ?

Worm:Win32/Vobfus.MQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment