Worm

About “Worm:Win32/Vobfus.E” infection

Malware Removal

The Worm:Win32/Vobfus.E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.E virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Worm:Win32/Vobfus.E?


File Info:

name: 2A44B792C984EBB9329D.mlw
path: /opt/CAPEv2/storage/binaries/fa19c6879f574842e13d714c3711ff9537e5ed932feb958f11002cb65226f7c0
crc32: 39E1891E
md5: 2a44b792c984ebb9329dcbdceea53760
sha1: 5a03d570e57d6bdc6e062627500874e6e6a2bcbb
sha256: fa19c6879f574842e13d714c3711ff9537e5ed932feb958f11002cb65226f7c0
sha512: bb10614d3561bd6a6164f69aa6ebb621e7426bedf75b81cbd00534c4061a36ccb294eb876ee0e2d0fcb13370c0277b11fa71a0f9702481fc410be8094cb6e84a
ssdeep: 768:Dqfko/XSBXKXorp8F9bdHXtHs7CQpcdHoCCvc:DpfXqod8F95NWee1vc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FD03D87B7704096ADD5AB239369786EB52E3A08D0F4B1B033661633DFC25E902D63B13
sha3_384: 74eaafc5c3e4fd0078df2a2260f52e2caee01cf0ee3a1d110f368f12e6fa3f78f0998cbc35e50a990abc2c423d030e73
ep_bytes: 6808124000e8f0ffffff000000000000
timestamp: 2000-01-01 12:00:00

Version Info:

Translation: 0x0409 0x04b0

Worm:Win32/Vobfus.E also known as:

BkavW32.AIDetectMalware
AVGWin32:AutoRun-AYY [Wrm]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Chinky.2
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.pt
McAfeeGeneric Packed.cn
MalwarebytesMalware.AI.4089298604
ZillyaWorm.AutoRun.Win32.123109
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( f1000d031 )
K7GWTrojan ( f1000d031 )
Cybereasonmalicious.2c984e
BaiduWin32.Worm.VB.t
VirITTrojan.Win32.Small.TV
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.FD
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Chinky-1
KasperskyWorm.Win32.Vobfus.eymh
BitDefenderGen:Trojan.Chinky.2
NANO-AntivirusTrojan.Win32.Autoruner.ebjruf
SUPERAntiSpywareTrojan.Agent/Gen-NameThief[Smart]
AvastWin32:AutoRun-AYY [Wrm]
TACHYONTrojan/W32.VB-Small.40960.G
SophosW32/SillyFDC-DS
F-SecureTrojan.TR/VB.bjd.2
DrWebWin32.HLLW.Autoruner.7225
VIPREGen:Trojan.Chinky.2
TrendMicroWORM_VB.SMP
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.2a44b792c984ebb9
EmsisoftGen:Trojan.Chinky.2 (B)
IkarusWorm.Win32.Vobfus
JiangminWorm/VBNA.hbww
VaristW32/VB.W.gen!Eldorado
AviraTR/VB.bjd.2
Antiy-AVLWorm/Win32.VBNA.a
MicrosoftWorm:Win32/Vobfus.E
XcitiumTrojWare.Win32.TrojanDropper.Multi.TD9@1ej374
ArcabitTrojan.Chinky.2
ZoneAlarmWorm.Win32.Vobfus.eymh
GDataGen:Trojan.Chinky.2
GoogleDetected
AhnLab-V3Worm/Win32.Basun.R1388
Acronissuspicious
VBA32TScope.Trojan.VB
ALYacGen:Trojan.Chinky.2
MAXmalware (ai score=82)
Cylanceunsafe
PandaW32/Vobfus.gen.worm
TrendMicro-HouseCallWORM_VB.SMP
RisingWorm.Win32.VB.wi (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.BDBD!tr
BitDefenderThetaAI:Packer.23FE57FB20
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudWorm:Win/Vobfus.26a8c9e4

How to remove Worm:Win32/Vobfus.E?

Worm:Win32/Vobfus.E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment