MalOb-HF should detect various Vundo/Cidox versions… your file comes from restore point according to its name, thus it’s difficult to assign it to some other malware traces…