Worm

Worm:Win32/Vobfus.RS removal instruction

Malware Removal

The Worm:Win32/Vobfus.RS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.RS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm:Win32/Vobfus.RS?


File Info:

name: 967341565629311BB89F.mlw
path: /opt/CAPEv2/storage/binaries/b5083801dceee321c70ddfe60e78a62895828867e930e1c9f359313d03ccb925
crc32: 969FBB8C
md5: 967341565629311bb89f5d51b4002cc6
sha1: 58129fa5a20426b99e076c816974b33eeb6b1e16
sha256: b5083801dceee321c70ddfe60e78a62895828867e930e1c9f359313d03ccb925
sha512: b9a49b0cc4d3917705c8f499f7c0c6eacfc779d9993bee8f8203e4b5e1c9835791f0bd6ee56dd90c84de8818e17bd34a0da0aebec169d66ef0dbd3f5545eff94
ssdeep: 3072:HWrbA13Ma0PLIiTFsgyZP/rV4D9tekTrE:2rU1KRQLiB8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T154A3A0106AC9E79FD1388BF1AF2A41A04435ED319DA3AE176AC16E093B75C8BC531773
sha3_384: f14df1e8dd329a37e1c7f0f8e9b3ca8d61d4062fe6b47f98a6159d92d04e48a7d038efff20c829983b7f62d54850a20d
ep_bytes: 68dc134000e8eeffffff0000ffcc3100
timestamp: 2013-09-09 04:28:02

Version Info:

LegalCopyright: ejaz
ProductName: wgvpznt
FileVersion: 5.72
ProductVersion: 5.72
InternalName: jsxob
OriginalFilename: jsxob.exe

Worm:Win32/Vobfus.RS also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner1.55527
MicroWorld-eScanGen:Variant.Barys.101
ClamAVWin.Trojan.VBGeneric-7165356-0
FireEyeGeneric.mg.967341565629311b
CAT-QuickHealTrojan.Beebone.D
MalwarebytesMalware.AI.709158897
ZillyaWorm.Vobfus.Win32.188021
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005042e71 )
K7GWTrojan ( 005042e71 )
Cybereasonmalicious.5a2042
BitDefenderThetaGen:NN.ZevbaF.36350.gq0@aSZ8BCai
VirITWorm.Win32.X-Autorun.DEDR
CyrenW32/A-24e16929!Eldorado
SymantecW32.Changeup!gen44
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.AMJN
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.eqbr
BitDefenderGen:Variant.Barys.101
NANO-AntivirusTrojan.Win32.Vobfus.dzobdh
SUPERAntiSpywareTrojan.Agent/Gen-Symmi
AvastWin32:Downloader-VGN [Trj]
SophosMal/SillyFDC-S
F-SecureWorm.WORM/Vobfus.ZNF
BaiduWin32.Trojan.Inject.ab
VIPREGen:Variant.Barys.101
McAfee-GW-EditionBehavesLike.Win32.Generic.nc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Barys.101 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Barys.101
JiangminWorm/Vobfus.ykv
WebrootW32.Obfuscated.Gen
AviraWORM/Vobfus.ZNF
Antiy-AVLWorm/Win32.Vobfus
XcitiumTrojWare.Win32.VB.ASKO@51fl9u
ArcabitTrojan.Barys.101
ZoneAlarmWorm.Win32.Vobfus.eqbr
MicrosoftWorm:Win32/Vobfus.RS
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.C171981
Acronissuspicious
VBA32TScope.Trojan.VB
MAXmalware (ai score=83)
Cylanceunsafe
APEXMalicious
RisingWorm.Vobfus!8.10E (TFE:2:9dlKpa1bz4J)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Refroso.AGEA!tr
AVGWin32:Downloader-VGN [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Vobfus.RS?

Worm:Win32/Vobfus.RS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment