Worm

What is “Worm.Win32.Vobfus.eeok”?

Malware Removal

The Worm.Win32.Vobfus.eeok is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.eeok virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm.Win32.Vobfus.eeok?


File Info:

name: 52C2AA3203DD48B1BF71.mlw
path: /opt/CAPEv2/storage/binaries/36e1fa1146926961fd6d4731d2802f167d7db3ff565e40b0b1607b771b398040
crc32: 2870A48D
md5: 52c2aa3203dd48b1bf71e34f1f5ca263
sha1: 63a1a9461eec614d724cf8552dcbf9a783fb5f7e
sha256: 36e1fa1146926961fd6d4731d2802f167d7db3ff565e40b0b1607b771b398040
sha512: bb6ec698c4fa47688356bdca08c9c76254157010b6ed8e3203b30176e5c1e6b9124952217ab6a3ecf56e2f2309f79b178709c3a41515440a9a0a4c6dffe33fbd
ssdeep: 3072:BaAfUEiTOrQKGcNqnGrD6uvIepyJS6f1Fre8:BhfiarQKGciwQJr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C1C3832A7691F63EC425C6F47D1A43A0906DAC3425D2AD13F7C25B2AB2F1EA7D321743
sha3_384: 18395c234bbcfc317dd6adf1b12982f01582375a6bbccc427804d6b34ec20a616c06ebec4221b56b97a91aea223e9702
ep_bytes: 688c374000e8f0ffffff000000000000
timestamp: 2011-07-26 02:31:38

Version Info:

Translation: 0x0409 0x04b0
ProductName: CkbWqjQnmFKq
FileVersion: 1.00
ProductVersion: 1.00
InternalName: cFmskSqkhLQbuvNA
OriginalFilename: cFmskSqkhLQbuvNA.exe

Worm.Win32.Vobfus.eeok also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.ls5o
DrWebTrojan.VbCrypt.60
MicroWorld-eScanGen:Heur.Conjar.1
FireEyeGeneric.mg.52c2aa3203dd48b1
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeVBObfus.g
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaMalware:Win32/km_2ff14.None
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderThetaAI:Packer.4CE058F020
VirITTrojan.Win32.Zyx.DA
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.AIU
APEXMalicious
TrendMicro-HouseCallMal_VBNA-7
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.eeok
BitDefenderGen:Heur.Conjar.1
NANO-AntivirusTrojan.Win32.Autoruner.covkvr
SUPERAntiSpywareTrojan.Agent/Gen-FakeAlert
AvastWin32:VB-YAI [Wrm]
TencentTrojan.Win32.VBKrypt.hae
TACHYONTrojan/W32.VBKrypt.126976
EmsisoftGen:Heur.Conjar.1 (B)
F-SecureWorm.WORM/Vobfus.DA.JH.1
BaiduWin32.Worm.Pronny.d
VIPREGen:Heur.Conjar.1
TrendMicroMal_VBNA-7
Trapminesuspicious.low.ml.score
SophosMal/VB-ABH
IkarusWorm.Gamarue
GoogleDetected
AviraWORM/Vobfus.DA.JH.1
VaristW32/Vobfus.W.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftWorm:Win32/Vobfus.DA
XcitiumTrojWare.Win32.VB.AYU@5b6t9v
ArcabitTrojan.Conjar.1
ZoneAlarmWorm.Win32.Vobfus.eeok
GDataGen:Heur.Conjar.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Diple.R9314
Acronissuspicious
VBA32Trojan.VBRA.023544
MAXmalware (ai score=85)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingWorm.VobfusEx!1.99E0 (CLASSIC)
YandexTrojan.GenAsa!jwdgXWS9k5Y
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.CNE!worm
AVGWin32:VB-YAI [Wrm]
DeepInstinctMALICIOUS
alibabacloudTrojan.Win.UnkAgent

How to remove Worm.Win32.Vobfus.eeok?

Worm.Win32.Vobfus.eeok removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment