Worm

Worm:Win32/Vobfus.YA removal

Malware Removal

The Worm:Win32/Vobfus.YA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.YA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A file with an unusual extension was attempted to be loaded as a DLL.
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm:Win32/Vobfus.YA?


File Info:

name: AFFE489803869F90C762.mlw
path: /opt/CAPEv2/storage/binaries/ae38cd0b126dd7291f81d83d81d81daa5b91a3d206bfb77b6c11739a780d1569
crc32: 2D5D1E19
md5: affe489803869f90c7628ba3921a650a
sha1: 09e2a3c9691e79f8d4a811cb4b956ed294a89b15
sha256: ae38cd0b126dd7291f81d83d81d81daa5b91a3d206bfb77b6c11739a780d1569
sha512: 80521d7edc85aaf2df54b895c490d9eb3842af44d2d266fa0158434a9b51294d38eb7b32fdafff6c5980b6041fc878eb6bb4f9f30baadea9fcbf7a40cd1e930c
ssdeep: 3072:tgQq3GAAkj5LFr/JYuqJSLLBGKByfRC1t:w3GXG1FGzo/kay5Cr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19CD39E29FA47C027E0115BF2569943D08BBDBD3329C3661BF7C566283AB31998491BF3
sha3_384: 4fa68e00c5d79c5fcbc6685452a385dbb1caa342d6f3d9a8637738e3ce11a11632873be32c1486a028a0164c24b671e5
ep_bytes: 68cc194000e8eeffffff000000000000
timestamp: 2014-07-16 12:15:42

Version Info:

Translation: 0x0409 0x04b0

Worm:Win32/Vobfus.YA also known as:

BkavW32.AIDetect.malware1
LionicWorm.Win32.Vobfus.lPJK
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Symmi.33043
FireEyeGeneric.mg.affe489803869f90
CAT-QuickHealTrojan.Beebone.D
ALYacGen:Variant.Symmi.33043
CylanceUnsafe
VIPREGen:Variant.Symmi.33043
SangforVISUAL BASIC4
K7AntiVirusTrojan ( 005042e71 )
K7GWTrojan ( 005042e71 )
Cybereasonmalicious.803869
BaiduWin32.Trojan.Inject.af
CyrenW32/Vobfus.OM.gen!Eldorado
SymantecW32.Changeup!gen46
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.AZED
APEXMalicious
ClamAVWin.Malware.Vobfus-6907383-0
KasperskyWorm.Win32.Vobfus.ertc
BitDefenderGen:Variant.Symmi.33043
NANO-AntivirusTrojan.Win32.Vobfus.dyhtkx
SUPERAntiSpywareTrojan.Agent/Gen-Rimecud
AvastWin32:VB-AHTQ [Trj]
Ad-AwareGen:Variant.Symmi.33043
EmsisoftGen:Variant.Symmi.33043 (B)
ComodoTrojWare.Win32.VB.ICOU@58gw6x
DrWebWin32.HLLW.Autoruner2.9946
ZillyaWorm.Vobfus.Win32.147972
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.ch
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/VB-ALW
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Symmi.33043
AviraTR/Badur.gyzq
Antiy-AVLTrojan/Generic.ASMalwS.488
ArcabitTrojan.Symmi.D8113
ZoneAlarmWorm.Win32.Vobfus.ertc
MicrosoftWorm:Win32/Vobfus.YA
CynetMalicious (score: 100)
McAfeeW32/Worm-AAEH.f!AFFE48980386
MAXmalware (ai score=89)
VBA32TScope.Trojan.VB
RisingTrojan.Win32.Generic.169FFECC (C64:YzY0Okk6Ih4yjfUx)
YandexWorm.Vobfus!6MRPc/MdYwg
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBInjector.W!tr
BitDefenderThetaGen:NN.ZevbaF.34582.im0@a4@PcMji
AVGWin32:VB-AHTQ [Trj]
PandaW32/Vobfus.GEP.worm
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Vobfus.YA?

Worm:Win32/Vobfus.YA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment