Worm

Worm.Win32.Vobfus.erof removal instruction

Malware Removal

The Worm.Win32.Vobfus.erof is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.erof virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.Vobfus.erof?


File Info:

name: BDD580B029FF7F5D881E.mlw
path: /opt/CAPEv2/storage/binaries/2cd022fd15e2ddeb1cfec0a63d18a2cca15d81179e699d8e8b73d70ea62068a4
crc32: 77F71CC7
md5: bdd580b029ff7f5d881efaef60ee9922
sha1: fc3fd54097c3118ff84440fb3af6247782697409
sha256: 2cd022fd15e2ddeb1cfec0a63d18a2cca15d81179e699d8e8b73d70ea62068a4
sha512: b4b006f8610c0c2f27a11fb68867ba92a3cf6591bea1383fadb1180658143512ef3819a1f728b99f41d0f1331bc953d89c59be7ac588a1b46bac17ea2e9b8a79
ssdeep: 6144:CaczcnqtrZjQCBBvfmge2uXOyDDaX66UEbuGHAceNEFKLrLRKD7ucfnxh4B7yCJY:Cafnqtti9K5CooEeOniot
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DE54911E7221EB38D43695F2208C03A551EC9977E4DB286FEBCBAA0936F0D976534743
sha3_384: 0db59af2634c2651202da6d5a0e8df7cc144afbc3897ab0d7b70f5c7061ddac90f377d1b8e1c5330753159e0769a9683
ep_bytes: 6854484000e8f0ffffff000000000000
timestamp: 2012-06-12 15:41:20

Version Info:

Translation: 0x0409 0x04b0
Comments: Smirkle
CompanyName: facioscapulohumeral Crowbar
FileDescription: prominent mahar sputiamo
LegalCopyright: dentinoblast Hunkerousness Rutch
LegalTrademarks: bleachhouse traverso gaspar
ProductName: flamboyantly unseam
FileVersion: 8.04
ProductVersion: 8.04
InternalName: xkmapiizclhz
OriginalFilename: xkmapiizclhz.exe

Worm.Win32.Vobfus.erof also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dh
McAfeeVBObfus.el
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.097c31
BitDefenderThetaGen:NN.ZevbaF.36744.sm0@a8@j2Pci
VirITWorm.Win32.Generic.CCUJ
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/AutoRun.VB.AQW
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.erof
BitDefenderGen:Variant.Symmi.769
NANO-AntivirusTrojan.Win32.WBNA.covkuw
MicroWorld-eScanGen:Variant.Symmi.769
AvastWin32:Evo-gen [Trj]
TencentWorm.Win32.Vobfus.n
SophosW32/Autorun-BXQ
BaiduWin32.Worm.Pronny.d
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.VbCrypt.81
VIPREGen:Variant.Symmi.769
TrendMicroWORM_VOBFUS.SMJO
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.bdd580b029ff7f5d
EmsisoftGen:Variant.Symmi.769 (B)
IkarusWorm.Win32.Vobfus
GDataGen:Variant.Symmi.769
WebrootTrojan.Win32.Diple
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.999
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Symmi.769
ViRobotTrojan.Win32.A.Diple.299008.BAT
ZoneAlarmWorm.Win32.Vobfus.erof
MicrosoftWorm:Win32/Vobfus
VaristW32/Vobfus.BE.gen!Eldorado
AhnLab-V3Worm/Win32.WBNA.R27996
Acronissuspicious
VBA32Malware-Cryptor.VB.gen
ALYacGen:Variant.Symmi.769
MAXmalware (ai score=83)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMJO
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!UvgZGdZJFQU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.W32.Diple.fjsw
FortinetW32/VBKrypt.C!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm.Win32.Vobfus.erof?

Worm.Win32.Vobfus.erof removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment