Worm

About “Worm:Win32/Vobfus.E” infection

Malware Removal

The Worm:Win32/Vobfus.E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.E virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Worm:Win32/Vobfus.E?


File Info:

name: 4CA49C3F6C629B7E92E9.mlw
path: /opt/CAPEv2/storage/binaries/730ec37ccb92f4b775a10ad8d856b9838c858f595df832b1909224c95463658d
crc32: A5694932
md5: 4ca49c3f6c629b7e92e96d83af53b99f
sha1: e8189fd96720b067e77e34303b03f0ff2a0673dd
sha256: 730ec37ccb92f4b775a10ad8d856b9838c858f595df832b1909224c95463658d
sha512: 9d07ba2b69de95c5c31712433c86b1c4ca3fdabcd2bf16465a0138053333259b8ef21a5adffc558a6ced3821eab716ca1a128b91f7ef3edcaa231ff339898276
ssdeep: 768:Uvfko/XuY3zktp8F9bdHXtHs7CQpcdHoCCvc:UEK3AL8F95NWee1vc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17303D63BB754091AEE5D723A329786DF12E3A0CC1F8B1B437621277DAC25E512D22B13
sha3_384: 2ae0e5d3c2c3921f72729fb387d8b21e3b03b748d176fe5badace704d07887f6a319761ccf18a60eee9597b4062d28fe
ep_bytes: 6808124000e8f0ffffff000000000000
timestamp: 2000-01-01 12:00:00

Version Info:

Translation: 0x0409 0x04b0

Worm:Win32/Vobfus.E also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Chinky.2
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.pt
McAfeeGeneric Packed.cn
Cylanceunsafe
VIPREGen:Trojan.Chinky.2
SangforSuspicious.Win32.Save.vb
K7AntiVirusNetWorm ( 700000151 )
K7GWNetWorm ( 700000151 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Chinky.2
BaiduWin32.Worm.VB.t
VirITTrojan.Win32.Small.TV
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.FD
APEXMalicious
TrendMicro-HouseCallWORM_VB.SMP
ClamAVWin.Trojan.Chinky-1
KasperskyWorm.Win32.Vobfus.eymh
BitDefenderGen:Trojan.Chinky.2
NANO-AntivirusTrojan.Win32.Autoruner.ebjruf
SUPERAntiSpywareTrojan.Agent/Gen-NameThief[Smart]
AvastWin32:AutoRun-AYY [Wrm]
EmsisoftGen:Trojan.Chinky.2 (B)
GoogleDetected
F-SecureTrojan.TR/VB.bjd.2
DrWebWin32.HLLW.Autoruner.7225
TrendMicroWORM_VB.SMP
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.4ca49c3f6c629b7e
SophosW32/SillyFDC-DS
SentinelOneStatic AI – Malicious PE
JiangminWorm/VBNA.hbww
VaristW32/VB.W.gen!Eldorado
AviraTR/VB.bjd.2
MAXmalware (ai score=85)
Antiy-AVLWorm/Win32.VBNA.a
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.TrojanDropper.Multi.TD9@1ej374
MicrosoftWorm:Win32/Vobfus.E
ZoneAlarmWorm.Win32.Vobfus.eymh
GDataGen:Trojan.Chinky.2
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Basun.R1388
Acronissuspicious
VBA32TScope.Trojan.VB
ALYacGen:Trojan.Chinky.2
TACHYONTrojan/W32.VB-Small.40960.G
MalwarebytesMalware.AI.4089298604
PandaW32/Vobfus.gen.worm
RisingWorm.Win32.VB.wi (CLASSIC)
YandexTrojan.GenAsa!NCN7rMc348E
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.BDBD!tr
BitDefenderThetaAI:Packer.23FE57FB20
AVGWin32:AutoRun-AYY [Wrm]
Cybereasonmalicious.f6c629
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.26a8c9e4

How to remove Worm:Win32/Vobfus.E?

Worm:Win32/Vobfus.E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment