Worm

Worm:Win32/Vobfus!E removal instruction

Malware Removal

The Worm:Win32/Vobfus!E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus!E virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

ns1.player1253.com
ns1.videoall.net
ns1.mediashares.org

How to determine Worm:Win32/Vobfus!E?


File Info:

crc32: 9E4D0B7F
md5: cf62ea628b9dc4afb4f2b68c3e94da52
name: CF62EA628B9DC4AFB4F2B68C3E94DA52.mlw
sha1: 679e80907ff0b10f0d358af50311387e4797ff44
sha256: c28e4d3788deaca217ffc93148b7df6e036a27e84ad6ce55c14b98e480b0c5f1
sha512: 5d50ca3e0dc6a8459d21e88fd1371500ec88fdc6768d9aa4ca90c9e4694d3ca5e7f7b38b84a406f95e80b7b6e509d0f059ea94801a55048d3a064427dfdd16d7
ssdeep: 3072:Tl08XgYg9bVtgfzFHfzb51QRPr8GDiyy:Tlng59joFJyr8Gux
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: eKGAy6904
FileVersion: 2.49
CompanyName: eKGAy6904
ProductName: eKGAy82
ProductVersion: 2.49
OriginalFilename: eKGAy6904.exe

Worm:Win32/Vobfus!E also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner.42131
MicroWorld-eScanGen:Variant.VBKrypt.23
FireEyeGeneric.mg.cf62ea628b9dc4af
Qihoo-360HEUR/QVM03.0.0510.Malware.Gen
McAfeeDownloader-CJX.gen.o
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan-Downloader ( 001ff72a1 )
BitDefenderGen:Variant.VBKrypt.23
K7GWTrojan-Downloader ( 001ff72a1 )
Cybereasonmalicious.28b9dc
BitDefenderThetaAI:Packer.34FBDFFB20
CyrenW32/VB.BR.gen!Eldorado
SymantecW32.Changeup!gen10
TotalDefenseWin32/Vobfus.I!generic
TrendMicro-HouseCallWORM_VBNA.SMTB
AvastWin32:VB-QRI [Drp]
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.dhos
NANO-AntivirusTrojan.Win32.Autoruner.coonjn
ViRobotTrojan.Win32.A.VBKrypt.258048.CN
Ad-AwareGen:Variant.VBKrypt.23
EmsisoftGen:Variant.VBKrypt.23 (B)
ComodoWorm.Win32.VB.YK@4on2wz
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Worm.AutoRun.cj
VIPRETrojan.Win32.Vobfus.a (v)
TrendMicroWORM_VBNA.SMTB
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dm
SophosML/PE-A + Mal/SillyFDC-I
IkarusTrojan.Win32.VBKrypt
JiangminTrojan/Generic.arygj
AviraTR/Dropper.Gen
MAXmalware (ai score=83)
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftWorm:Win32/Vobfus.gen!E
ArcabitTrojan.VBKrypt.23
SUPERAntiSpywareTrojan.Agent/Gen-Trafog
ZoneAlarmWorm.Win32.Vobfus.dhos
GDataGen:Variant.VBKrypt.23
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VBKrypt.R2546
Acronissuspicious
ALYacGen:Variant.VBKrypt.23
TACHYONTrojan/W32.VB-Krypt.258048
VBA32Trojan.VBRA.07070
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaGeneric Malware
APEXMalicious
ESET-NOD32Win32/AutoRun.VB.YK
RisingWorm.Agent!1.D163 (CLASSIC)
YandexTrojan.GenAsa!kzGc1bM1Y3c
SentinelOneStatic AI – Malicious PE – Worm
eGambitUnsafe.AI_Score_99%
FortinetW32/AutoRun.XM!worm
AVGWin32:VB-QRI [Drp]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Worm:Win32/Vobfus!E?

Worm:Win32/Vobfus!E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment