Worm

What is “Worm:Win32/Vobfus!pz”?

Malware Removal

The Worm:Win32/Vobfus!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Vobfus!pz?


File Info:

name: 1DFAAB7C7C5956FE7EC1.mlw
path: /opt/CAPEv2/storage/binaries/98e9dc94ccb764fc2631d64bd68ec6911048c2aeba6a4c36134e6e027bc5cde9
crc32: 9E681B3E
md5: 1dfaab7c7c5956fe7ec136f62fa0be0e
sha1: 9b62898c36d75e0d3cb1cc1611d4a1fe07d81602
sha256: 98e9dc94ccb764fc2631d64bd68ec6911048c2aeba6a4c36134e6e027bc5cde9
sha512: c2075d939eb6135270c39d93181179a715522ff1fba259f8baf30d7a8eaff4bd02e87fb4d3b3220bd4d033f225c2a557f553158f8fbab06c2a16292bed70d3ba
ssdeep: 1536:H2tkjtTQxjU0GgAJx1kNmKldcBP9Vel+Fk0EE:kkjyxjU0GgAX9j
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E2142D7F7B5A0468E4746678A2E7F3D23BD2B0484E17C2A6772417695C8BE321C2CB53
sha3_384: a62b95129df92bb7f4d1ccb8af0549b82d5ab6a33191a7ddc3934e533aa709bfcb13bd94429ebb4f6aabf83636fc928c
ep_bytes: 6884124000e8eeffffff000000000000
timestamp: 2012-04-13 01:38:28

Version Info:

0: [No Data]

Worm:Win32/Vobfus!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKDZ.94870
ClamAVWin.Trojan.VB-1667
FireEyeGeneric.mg.1dfaab7c7c5956fe
CAT-QuickHealTrojan.Beebone.D
McAfeeW32/Autorun.worm.aaeh
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.c36d75
BitDefenderThetaGen:NN.ZevbaF.36662.mmZ@aqxdPcf
CyrenW32/Vobfus.AO.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.AUR
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.SuperThreat.l
BitDefenderTrojan.GenericKDZ.94870
NANO-AntivirusTrojan.Win32.SuperThreat.cqkxoe
AvastWin32:VB-ACHU [Trj]
TencentWorm.Win32.Vobfus.d
TACHYONTrojan/W32.VB-SuperThreat.200704.B
EmsisoftTrojan.GenericKDZ.94870 (B)
BaiduWin32.Worm.Autorun.v
F-SecureTrojan.TR/Vobfus.126976.26
DrWebWin32.HLLW.Autoruner1.15281
VIPRETrojan.GenericKDZ.94870
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cz
Trapminemalicious.high.ml.score
SophosW32/SillyFDC-HW
IkarusTrojan.Patched
GDataTrojan.GenericKDZ.94870
AviraTR/Vobfus.126976.26
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.VB.AUP@4obluj
ArcabitTrojan.Generic.D17296
ZoneAlarmTrojan.Win32.SuperThreat.l
MicrosoftWorm:Win32/Vobfus!pz
GoogleDetected
AhnLab-V3Trojan/Win.Jorik.R569020
Acronissuspicious
VBA32TScope.Trojan.VB
ALYacTrojan.GenericKDZ.94870
MAXmalware (ai score=82)
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
RisingTrojan.Win32.VBCode.fsw (CLASSIC)
YandexTrojan.GenAsa!bu9gYp/1wsQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-ACHU [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm:Win32/Vobfus!pz?

Worm:Win32/Vobfus!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment