Worm

Worm:Win32/Vobfus.EW information

Malware Removal

The Worm:Win32/Vobfus.EW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.EW virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm:Win32/Vobfus.EW?


File Info:

name: EF4019FA56F239292C1A.mlw
path: /opt/CAPEv2/storage/binaries/02f6dd9e00401b7815f9aa2b528aee9685df74fcbc541bbbc416faef790de9f1
crc32: 90D9B542
md5: ef4019fa56f239292c1a50eeb0ac7e3b
sha1: ee9e8a8767fe3050aa9263db44715421fa945e1a
sha256: 02f6dd9e00401b7815f9aa2b528aee9685df74fcbc541bbbc416faef790de9f1
sha512: cbe47f2028f227ba3c19244c246eb457c8c6e3147d462b20f090c4bf258567e9348b9bea9b52db2dd06907c10ee501a423df1b1fa99a896ef4984b4388255708
ssdeep: 6144:YK4o3dwqsNy5ibpNjl4EqxF6snji81RUinKICui:N4SdQxlX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14334D7A77B719888F418157058F3C3F23796EC4D494B520B6B243E2A3FBBE652D24A53
sha3_384: a7494faf2abf24145546836f869f566cf0b271171dae51de95da278b478d8f9b7cbd67def587506209a0c91dbc18d806
ep_bytes: 688c124000e8eeffffff000000000000
timestamp: 2012-05-04 05:48:36

Version Info:

Translation: 0x0409 0x04b0
ProductName: jsxwjoj
FileVersion: 7.08.0002
ProductVersion: 7.08.0002
InternalName: zchgcnyhcs
OriginalFilename: zchgcnyhcs.exe

Worm:Win32/Vobfus.EW also known as:

Elasticmalicious (high confidence)
DrWebTrojan.MulDrop3.48626
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Beebone.D
McAfeeVBObfus.dv
MalwarebytesGeneric.Worm.AutoRun.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.a56f23
BitDefenderThetaGen:NN.ZevbaF.36196.om0@aejF1Igi
VirITTrojan.Win32.Cryptor.A
CyrenW32/Vobfus.O.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.AVN
APEXMalicious
ClamAVWin.Malware.Vobfus-9940378-0
KasperskyTrojan.Win32.Vobfus.sln
BitDefenderTrojan.GenericKDZ.98339
NANO-AntivirusTrojan.Win32.Vobfus.cqkxvu
SUPERAntiSpywareTrojan.Agent/Gen-Vban
MicroWorld-eScanTrojan.GenericKDZ.98339
AvastWin32:VB-ADDH [Trj]
TencentWorm.Win32.Vobfus.n
EmsisoftTrojan.GenericKDZ.98339 (B)
F-SecureWorm.WORM/Vobfus.ew.jh
BaiduWin32.Worm.Autorun.af
VIPRETrojan.GenericKDZ.98339
TrendMicroWORM_VOBFUS.SM00
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dt
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.ef4019fa56f23929
SophosW32/Vobfus-AN
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.98339
JiangminTrojan/Vbobf.b
AviraWORM/Vobfus.ew.jh
MAXmalware (ai score=87)
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Generic.D18023
ViRobotTrojan.Win32.A.VB.233472.O
ZoneAlarmTrojan.Win32.Vobfus.sln
MicrosoftWorm:Win32/Vobfus.EW
GoogleDetected
AhnLab-V3Trojan/Win32.VB.R24629
VBA32SScope.Malware-Cryptor.VBCR.3042
ALYacTrojan.GenericKDZ.98339
TACHYONTrojan/W32.Vobfus.233472
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SM00
RisingTrojan.FakeIcon!1.64A2 (CLASSIC)
IkarusWorm.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Jorik.EGLG!tr
AVGWin32:VB-ADDH [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm:Win32/Vobfus.EW?

Worm:Win32/Vobfus.EW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment