Worm

How to remove “Worm:Win32/Vobfus.SZ”?

Malware Removal

The Worm:Win32/Vobfus.SZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.SZ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm:Win32/Vobfus.SZ?


File Info:

name: B74FD27EFF8D51FEB70D.mlw
path: /opt/CAPEv2/storage/binaries/7c9ad89c8f181e1e510b454af6e251e81b443a3140e7c9c4274a9f4888242643
crc32: 15C04220
md5: b74fd27eff8d51feb70d5ca610c4b040
sha1: 42134e0a8171ece1b4917f4c393a24b0149439a2
sha256: 7c9ad89c8f181e1e510b454af6e251e81b443a3140e7c9c4274a9f4888242643
sha512: 0aaa43e256b3a86547511d6a78f0de70c4c70faf87fec1ce161c714141ea04924c30c5089725f6b54224a3eb15499216d7993dbfac2ee67578f877703af9792e
ssdeep: 1536:QWqt9NEPrcCDn3pJebp16KAFfhGH+BVuhnMFhAkU6mDzeHzs94CS7FRK1+Rzf8yy:Qt9rQnPeFjqoH+cMbZJ/syN7bu+Zvy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T144D39D07FB959D95CD4D07F2896B63989A2BA0601F0A5F3B7704262C2CF37914DA738E
sha3_384: 1bba8b97d57bd4b3fb22f66ca7dbe5adf75cd9cabb5769b7630198ff7a3c5d4826c4acb2f321fefd8dbccd12be99cc9d
ep_bytes: 6830174000e8eeffffff000040000000
timestamp: 2013-08-20 05:12:46

Version Info:

ProductName: fwgtdm
FileVersion: 9.03
ProductVersion: 9.03
InternalName: quayu
OriginalFilename: quayu.exe

Worm:Win32/Vobfus.SZ also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Vobfus.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.127276
ClamAVWin.Trojan.Vobfus-69628
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.PWSZbot.ch
McAfeeW32/Autorun.worm.tk!pheur
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.Vobfus.Win32.33329
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f5e11 )
AlibabaWorm:Win32/Vobfus.e3448281
K7GWTrojan ( 0040f5e11 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecW32.Changeup
ESET-NOD32a variant of Win32/Injector.ALGI
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Vobfus.vkh
BitDefenderGen:Variant.Midie.127276
NANO-AntivirusTrojan.Win32.cbygvj.eaqdvl
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-AIDB [Trj]
TencentWin32.Trojan.Vobfus.Ztjl
EmsisoftGen:Variant.Midie.127276 (B)
F-SecureTrojan.TR/Dropper.VB.Gen
DrWebWin32.HLLW.Autoruner1.54706
VIPREGen:Variant.Midie.127276
TrendMicroWORM_VOBFUS.SML1
FireEyeGeneric.mg.b74fd27eff8d51fe
SophosMal/VBCheMan-F
GDataGen:Variant.Midie.127276
JiangminTrojan/Vobfus.qpx
GoogleDetected
AviraTR/Dropper.VB.Gen
MAXmalware (ai score=100)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.998
XcitiumTrojWare.Win32.VB.SKM@50t0uy
ArcabitTrojan.Midie.D1F12C
ZoneAlarmTrojan.Win32.Vobfus.vkh
MicrosoftWorm:Win32/Vobfus.SZ
VaristW32/Vobfus.KT.gen!Eldorado
AhnLab-V3Trojan/Win32.Vobfus.R79895
BitDefenderThetaGen:NN.ZevbaF.36744.iu1@aywUXjbi
ALYacGen:Variant.Midie.127276
TACHYONTrojan/W32.VB-Vobfus.136749
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SML1
RisingWorm.Vobfus!1.9EC9 (CLASSIC)
YandexTrojan.Vobfus!ut6UimoPsHk
IkarusTrojan.Win32.Vobfus
MaxSecureTrojan.Malware.6251726.susgen
FortinetW32/Injector.VOX!tr
AVGWin32:VB-AIDB [Trj]
Cybereasonmalicious.a8171e
DeepInstinctMALICIOUS

How to remove Worm:Win32/Vobfus.SZ?

Worm:Win32/Vobfus.SZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment