Worm

Worm.Win32.Vobfus.eicn removal instruction

Malware Removal

The Worm.Win32.Vobfus.eicn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.eicn virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm.Win32.Vobfus.eicn?


File Info:

name: E5BEFF0F983A424AB406.mlw
path: /opt/CAPEv2/storage/binaries/1f5b27750e5185220672e9446f6ad2ae729f47f92ecb0105e7f15b618c6cc25c
crc32: 03D65C8F
md5: e5beff0f983a424ab4067de81dd92dfa
sha1: 2d150573ff72e5a8b857923aa712110647362184
sha256: 1f5b27750e5185220672e9446f6ad2ae729f47f92ecb0105e7f15b618c6cc25c
sha512: d3dd099d6050b1290b4921ceb0cf158eea5a3103e98a6d972012978840e03082798bc68adf05053eca2bdc1defd31e058df50fdf4321381b1b1b0c5f3984d0f7
ssdeep: 6144:SzY89mZ9wKpYdGizwhGt7k9dcKCdEkR2OAkmQxkpnUMgpmDJOGExOfKdLK/P2SQY:Cc91uukRX8WkpnUMuGExOfW+/P2SQ/g
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15194A316AA10703FF956C5B01966AB96A41C2E7A1780FC0BB780BF1974716E7B2F071F
sha3_384: 0d6b45fa24fbf8ce81f524fadd51f075158eb11af89f41159b236be1444ef1784d3d3820c7d0c94513aae68ae2252452
ep_bytes: 68a04f4000e8f0ffffff000000000000
timestamp: 2012-03-07 00:10:53

Version Info:

Translation: 0x0409 0x04b0
ProductName: OBtHqXC
FileVersion: 1.00
ProductVersion: 1.00
InternalName: lfWoUewA
OriginalFilename: lfWoUewA.exe

Worm.Win32.Vobfus.eicn also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Chinky.7
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.gm
McAfeeGeneric VB.kk
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.f983a4
BaiduWin32.Worm.Autorun.l
VirITWorm.Win32.Autorun.DX
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.AQW
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SM03
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.eicn
BitDefenderGen:Variant.Chinky.7
NANO-AntivirusTrojan.Win32.WBNA.cnwqpx
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ABOE [Trj]
TencentWorm.Win32.Vobfus.n
EmsisoftGen:Variant.Chinky.7 (B)
F-SecureTrojan.TR/Otran.azuvnb
DrWebTrojan.VbCrypt.81
VIPREGen:Variant.Chinky.7
TrendMicroWORM_VOBFUS.SM03
FireEyeGeneric.mg.e5beff0f983a424a
SophosMal/VBCheMan-B
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=86)
JiangminWorm.Vobfus.kssl
GoogleDetected
AviraTR/Otran.azuvnb
VaristW32/VB.FV.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.985
MicrosoftWorm:Win32/Vobfus!pz
XcitiumTrojWare.Win32.Diple.EMIB@4pez3w
ArcabitTrojan.Chinky.7
ZoneAlarmWorm.Win32.Vobfus.eicn
GDataWin32.Worm.Vobfus.L
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Vobfus.R81881
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36802.zm1@aiyB9Cci
ALYacGen:Variant.Chinky.7
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaW32/Vobfus.GEP.worm
RisingWorm.VobfusEx!1.99DC (CLASSIC)
YandexTrojan.GenAsa!lcwhJF4s3Ns
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-ABOE [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan.Win.Generic.b60bc517

How to remove Worm.Win32.Vobfus.eicn?

Worm.Win32.Vobfus.eicn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment