Worm

Worm.Win32.Vobfus.eoc removal guide

Malware Removal

The Worm.Win32.Vobfus.eoc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.eoc virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.Vobfus.eoc?


File Info:

name: 922DB35324EC4877ED3B.mlw
path: /opt/CAPEv2/storage/binaries/e8afaaa420a94161b97c709b91043fc6289b4c2f84a8a781af6c8852052d4b02
crc32: 915DF17B
md5: 922db35324ec4877ed3b8aafed927b70
sha1: b878854bd9bcbe257ae94b6dd62ca6ab8fcfed08
sha256: e8afaaa420a94161b97c709b91043fc6289b4c2f84a8a781af6c8852052d4b02
sha512: fa3121751cc9c7f9c10fcc9cad41ef9388017f5e122555ed3f06f28c84b0d6433189b9459bf0489d487c51dcf2e5f3ce4ba22c652b8fcc17838704d45f09bedd
ssdeep: 1536:aLXJrEys7cv+cYgBtKH67bU8TkWRifJYwdtmP+7m5KFbwQL4AW3lV4ckUl0OEZCw:KBR+cYgB4ZCchor5KFjkF/5YC6IJnnAB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D2F3093ABA868A5DD759167028E7C7F213B3742A5F07490B3684376A2CB1F342E5DB43
sha3_384: 9f156cb0f21f779a4074dce2ced5b01aef961ab1f262e5baba2711df340c2f1921339e109ad9a79ca799a326e18316cc
ep_bytes: 68d4174000e8f0ffffff000050000000
timestamp: 2012-09-21 17:40:54

Version Info:

Translation: 0x0409 0x04b0
ProductName: radiasti
FileVersion: 4.03
ProductVersion: 4.03
InternalName: wreathe
OriginalFilename: wreathe.exe

Worm.Win32.Vobfus.eoc also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.950
FireEyeGeneric.mg.922db35324ec4877
CAT-QuickHealTrojan.VBCrypt.MF.9734
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeVBObfus.dv
MalwarebytesPronny.Worm.Spreader.DDS
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (D)
K7GWEmailWorm ( 0040f60d1 )
K7AntiVirusTrojan ( 005640b91 )
BitDefenderThetaGen:NN.ZevbaF.36802.km0@ayo1vYki
VirITTrojan.Win32.Generic.CELD
SymantecW32.Changeup!gen20
tehtrisGeneric.Malware
ESET-NOD32Win32/Pronny.EL
APEXMalicious
AvastWin32:VB-AENN [Trj]
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.eoc
BitDefenderGen:Variant.Barys.950
NANO-AntivirusTrojan.Win32.Vobfus.cfdsnd
RisingTrojan.VB!1.99F7 (CLASSIC)
EmsisoftGen:Variant.Barys.950 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.VbCrypt.81
VIPREGen:Variant.Barys.950
TrendMicroWORM_VOBFUS.SM02
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-Y
IkarusWorm.Win32.Vobfus
GDataWin32.Trojan.VB.SE
JiangminWorm.Vobfus.ptsd
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=89)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.993
XcitiumWorm.Win32.Pronny.ABQ@4puwz1
ArcabitTrojan.Barys.950
ViRobotWorm.Win32.A.Vobfus.172032.A
ZoneAlarmWorm.Win32.Vobfus.eoc
MicrosoftWorm:Win32/Vobfus.IG
VaristW32/VB.HE.gen!Eldorado
AhnLab-V3Worm/Win32.Vobfus.R38810
Acronissuspicious
VBA32Worm.Vobfus
ALYacGen:Variant.Barys.950
TACHYONWorm/W32.Vobfus.172032.B
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM02
TencentWorm.Win32.Vobfus.q
YandexTrojan.GenAsa!AWbSy/YbgE4
SentinelOneStatic AI – Malicious PE
FortinetW32/Diple.EJQE!tr
AVGWin32:VB-AENN [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan.Win.UnkAgent

How to remove Worm.Win32.Vobfus.eoc?

Worm.Win32.Vobfus.eoc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment