Worm

About “Worm:Win32/Vobfus!T” infection

Malware Removal

The Worm:Win32/Vobfus!T is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus!T virus can do?

  • Executable code extraction
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to disable Windows Auto Updates
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

ns1.spansearcher.net

How to determine Worm:Win32/Vobfus!T?


File Info:

crc32: 65FF7009
md5: 4375f35f6cd2b6b41dd8bd7fe0e37554
name: 4375F35F6CD2B6B41DD8BD7FE0E37554.mlw
sha1: 05c55737d39b10324c82a86488e689e805b50630
sha256: 8c0831e99f7041e56b93bc7c1b2777c30889086f978560ede5d16bd494ac4434
sha512: dd6b94919cc2b7a8f41605392956f8ccd8af9e455aeed27e5bf17b0d3927280b144596ad969be802a474f35ccb293a7719beca2924b789e0149e6bad9bd1538e
ssdeep: 6144:9mbQ94pWymPBeaSAOJ+7xi5eRed63qaCR8nIBX1:IcsLmPBeaSAOJ+7xi5eRed63qaCB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: onTkiV
FileVersion: 1.00
OriginalFilename: onTkiV.exe
ProductName: IGCkox

Worm:Win32/Vobfus!T also known as:

BkavW32.AIDetect.malware1
K7AntiVirusEmailWorm ( 0054d10f1 )
Elasticmalicious (high confidence)
DrWebTrojan.VbCrypt.81
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Beebone.D
ALYacGen:Variant.Chinky.7
CylanceUnsafe
SangforWin.Trojan.Changeup-6169544-0
CrowdStrikewin/malicious_confidence_100% (D)
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.f6cd2b
BaiduWin32.Worm.Pronny.d
CyrenW32/Vobfus.AI.gen!Eldorado
SymantecW32.Changeup
ESET-NOD32Win32/Pronny.AD
APEXMalicious
AvastWin32:VB-ABLQ [Trj]
ClamAVWin.Packer.VBCrypt-5731517-0
KasperskyWorm.Win32.Vobfus.aigr
BitDefenderGen:Variant.Chinky.7
NANO-AntivirusTrojan.Win32.WBNA.chvyyd
ViRobotWorm.Win32.A.WBNA.204800.W
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
MicroWorld-eScanGen:Variant.Chinky.7
TencentWorm.Win32.Vobfus.n
Ad-AwareGen:Variant.Chinky.7
SophosML/PE-A + Mal/VBCheMan-B
ComodoTrojWare.Win32.VB.AVA@4paxk7
BitDefenderThetaGen:NN.ZevbaF.34690.mm0@aafVLTpi
VIPRETrojan.Win32.Generic!SB.0
TrendMicroWORM_VOBFUS.SMAB
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dm
FireEyeGeneric.mg.4375f35f6cd2b6b4
EmsisoftGen:Variant.Chinky.7 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Chinky.755684
eGambitUnsafe.AI_Score_99%
MicrosoftWorm:Win32/Vobfus.gen!T
ArcabitTrojan.Chinky.7
GDataGen:Variant.Chinky.7
TACHYONWorm/W32.Vobfus.204800.E
AhnLab-V3Worm/Win32.WBNA.R21557
Acronissuspicious
McAfeeGeneric VB.kk
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Blocker
MalwarebytesWorm.Obfuscator
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMAB
RisingTrojan.Win32.Generic.15A18C4F (C64:YzY0OrppPlePj2KN)
YandexTrojan.GenAsa!V+F2Msh0F64
IkarusTrojan.Win32.Otran
MaxSecureVirus.Virus.W32.VB.R5
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-ABLQ [Trj]
Paloaltogeneric.ml

How to remove Worm:Win32/Vobfus!T?

Worm:Win32/Vobfus!T removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment