Worm

Worm.Win32.Vobfus.egau removal tips

Malware Removal

The Worm.Win32.Vobfus.egau is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.egau virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm.Win32.Vobfus.egau?


File Info:

name: DDC674090430791A8355.mlw
path: /opt/CAPEv2/storage/binaries/79c5602d72304331a529ac08560f4fc0330591f7447f216da7c88afe95d91909
crc32: 9FC4051A
md5: ddc674090430791a835548e94ee98c93
sha1: dc17e218d7e2f3d550e2ee340a0b8a678f74c65f
sha256: 79c5602d72304331a529ac08560f4fc0330591f7447f216da7c88afe95d91909
sha512: e2aa8fe0ca11cb2d355491da857e520301c122b27996fd5eece344c2110f4ba7f58edfa487527cbfae444a3b8728c5f9bab2e5eb8b9986fe9947bba543dd9121
ssdeep: 3072:OUVeHqI2zh7sAFEouHwbBAW4hXNacd6HFfak/K4jaU3bxK2E0:O83I2z/FEouH+BAz4HFfAgLjX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CC548421AB11617BF945C6F0682AAB66651C2E370BD5EC47B340BFA964712E3B1F070F
sha3_384: 539ca822b3be6d341df7b409e4220d1a889c563edcf0b544ec97af58855c68743dc235673d94687b9d08a2045f84cc87
ep_bytes: 68a0404000e8eeffffff000000000000
timestamp: 2012-03-05 19:02:30

Version Info:

Translation: 0x0409 0x04b0
ProductName: khhpnftgt
FileVersion: 1.00
ProductVersion: 1.00
InternalName: SzgCrvga
OriginalFilename: SzgCrvga.exe

Worm.Win32.Vobfus.egau also known as:

BkavW32.AIDetectMalware
AVGWin32:AutoRun-CSL [Wrm]
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.95998
FireEyeGeneric.mg.ddc674090430791a
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.df
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKDZ.95998
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.904307
BitDefenderThetaGen:NN.ZevbaF.36802.sm0@aOuqWYgi
VirITTrojan.Win32.Zyx.IQ
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.ASS
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.egau
BitDefenderTrojan.GenericKDZ.95998
NANO-AntivirusTrojan.Win32.Vobfus.cydsbq
SUPERAntiSpywareTrojan.Agent/Gen-Vban
AvastWin32:AutoRun-CSL [Wrm]
TencentWorm.Win32.Vobfus.n
TACHYONWorm/W32.Vobfus.303104.B
SophosMal/VBCheMan-B
BaiduWin32.Worm.Autorun.l
F-SecureWorm.WORM/Vobfus.S.300
DrWebTrojan.VbCrypt.81
TrendMicroWORM_VOBFUS.SMIH
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.95998 (B)
IkarusWorm.Win32.Vobfus
JiangminWorm/Vobfus.gim
VaristW32/Vobfus.BE.gen!Eldorado
AviraWORM/Vobfus.S.300
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.998
MicrosoftWorm:Win32/Vobfus!pz
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Generic.D176FE
ZoneAlarmWorm.Win32.Vobfus.egau
GDataTrojan.GenericKDZ.95998
GoogleDetected
AhnLab-V3Trojan/Win32.VBKrypt.R22390
Acronissuspicious
VBA32Trojan.VB.01619
ALYacTrojan.GenericKDZ.95998
MAXmalware (ai score=85)
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMIH
RisingWorm.VobfusEx!1.99DC (CLASSIC)
YandexTrojan.GenAsa!w9h52XWjC88
SentinelOneStatic AI – Malicious PE
FortinetW32/VBKrypt.C!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudWorm:Win/Vobfus.55b71eef

How to remove Worm.Win32.Vobfus.egau?

Worm.Win32.Vobfus.egau removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment