Worm

Worm.Win32.Vobfus.eewh removal instruction

Malware Removal

The Worm.Win32.Vobfus.eewh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.eewh virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.Vobfus.eewh?


File Info:

name: 721598781B792BCC9918.mlw
path: /opt/CAPEv2/storage/binaries/d39be49afc8a49c27a3ae74bfbd0832c7c8538df378ad5a2284853dedbc9e933
crc32: 0F7C3754
md5: 721598781b792bcc9918299c066e7a8c
sha1: 81fa7721bea9bb1c48da2e8645ab1f08def7aa29
sha256: d39be49afc8a49c27a3ae74bfbd0832c7c8538df378ad5a2284853dedbc9e933
sha512: 193d5b38777fb1eafc22b818bc2fabd35c2b85ecb3fefcd7d379a36e1de102a83f3d144b7c1ee7699026da13e76ebb96f70af333e81a7475410c7daddee3d4dd
ssdeep: 3072:phUFgCTQtKrueiygR4O6avJamof44oQZiEdq:egCQtKSMgR56avUm9Wy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T100E3A32E7691F33AC415CAF43D1A8294A07DEC3225E26C17F7C26B1676B1DABD220753
sha3_384: 6f962cbb03de7fd8bd4480d2430991fd2244a0f1601f6936f882ccf8b1a4ba7db868216661e3a6dc9a81acfe27524a3c
ep_bytes: 6878334000e8f0ffffff000000000000
timestamp: 2011-09-18 02:18:44

Version Info:

Translation: 0x0409 0x04b0
ProductName: BxYzCUXtjaswjj
FileVersion: 1.00
ProductVersion: 1.00
InternalName: JQJicfgw
OriginalFilename: JQJicfgw.exe

Worm.Win32.Vobfus.eewh also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebTrojan.VbCrypt.60
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Vobfus.gen
McAfeeVBObfus.bn
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.81b792
BitDefenderThetaAI:Packer.45FD06F920
VirITWorm.Win32.Generic.AZMH
CyrenW32/Vobfus.V.gen!Eldorado
SymantecW32.Changeup!gen15
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.ALS
APEXMalicious
ClamAVWin.Trojan.Diple-8424
KasperskyWorm.Win32.Vobfus.eewh
BitDefenderGen:Variant.Barys.2424
NANO-AntivirusTrojan.Win32.WBNA.covkfo
SUPERAntiSpywareTrojan.Agent/Gen-Vban
MicroWorld-eScanGen:Variant.Barys.2424
AvastWin32:VB-ABDC [Drp]
TencentTrojan.Win32.Koobface.p
EmsisoftGen:Variant.Barys.2424 (B)
F-SecureTrojan.TR/Spy.Agent.155646
BaiduWin32.Trojan.Inject.n
VIPREGen:Variant.Barys.2424
TrendMicroWORM_VOBFUS.SMHE
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.721598781b792bcc
SophosMal/VB-XV
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Barys.2424
AviraTR/Spy.Agent.155646
MAXmalware (ai score=88)
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Barys.D978
ZoneAlarmWorm.Win32.Vobfus.eewh
MicrosoftWorm:Win32/Vobfus.gen!N
GoogleDetected
AhnLab-V3Trojan/Win32.Diple.R13793
VBA32TScope.Trojan.VB
ALYacGen:Variant.Barys.2424
TACHYONWorm/W32.Vobfus.155648.I
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMHE
RisingWorm.Vobfus!1.99C7 (CLASSIC)
IkarusWorm.Win32.WBNA
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.CNE!worm
AVGWin32:VB-ABDC [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm.Win32.Vobfus.eewh?

Worm.Win32.Vobfus.eewh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment