Worm

About “Worm.Win32.Vobfus.efde” infection

Malware Removal

The Worm.Win32.Vobfus.efde is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.efde virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.Vobfus.efde?


File Info:

name: 0F4F5326CF14FEB67B40.mlw
path: /opt/CAPEv2/storage/binaries/c14dbc6c4fd4fbb377cd666b7cef7e48b42ff212eb27ef27c79c1f01bdb2387a
crc32: 4F01D215
md5: 0f4f5326cf14feb67b40872fdc0f9e71
sha1: 952c4e4011c7f68d9653036b73b0cc7cc1167e3f
sha256: c14dbc6c4fd4fbb377cd666b7cef7e48b42ff212eb27ef27c79c1f01bdb2387a
sha512: a51c58b2a427e44d03162bdcaffb6d79e577eba0c6f73c549818066bcaddc47da7b20bcc0e2a727e2322043c7e1b403e2c52ded20941961a55a30e0f38d4f77a
ssdeep: 3072:ryhC1Q8Od5yi7a6LE7WTdl//8hWYbbLlr:rGt7IiG6LEqfsFr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T194C3A42972D0F63BC425C6F83D1A43A4806EAD3415A1AD13F7D65F16B3F2EA79222743
sha3_384: 022ef7798e1c78259410d4484feb54820657cbe60caf3d5ca39992d2e296608499b7d160443546c2498eb1650d19c708
ep_bytes: 6810314000e8eeffffff000000000000
timestamp: 2011-07-13 11:50:02

Version Info:

Translation: 0x0409 0x04b0
ProductName: FvOGHbTJE
FileVersion: 1.00
ProductVersion: 1.00
InternalName: TTdnMsucFxYH
OriginalFilename: TTdnMsucFxYH.exe

Worm.Win32.Vobfus.efde also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lr3L
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.0f4f5326cf14feb6
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.cm
ALYacGen:Variant.Chinky.6
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Vobfus.ac570433
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.6cf14f
BaiduWin32.Worm.VB.ov
VirITTrojan.Win32.SHeur3.CJKG
SymantecW32.Changeup!gen35
ESET-NOD32Win32/AutoRun.VB.AHZ
APEXMalicious
ClamAVWin.Worm.Vobfus-7192126-0
KasperskyWorm.Win32.Vobfus.efde
BitDefenderGen:Variant.Chinky.6
NANO-AntivirusTrojan.Win32.Vobfus.csfhlp
SUPERAntiSpywareTrojan.Agent/Gen-Backdoor
MicroWorld-eScanGen:Variant.Chinky.6
AvastWin32:VB-ABDC [Drp]
TencentTrojan.Win32.Vbkrypt.pa
TACHYONTrojan/W32.VBKrypt.126976.B
SophosMal/VB-XV
F-SecureTrojan.TR/ATRAPS.Gen2
DrWebTrojan.VbCrypt.60
VIPREGen:Variant.Chinky.6
TrendMicroMal_VBNA-7
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Chinky.6 (B)
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/ATRAPS.Gen2
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
ArcabitTrojan.Chinky.6
ZoneAlarmWorm.Win32.Vobfus.efde
GDataGen:Variant.Chinky.6
VaristW32/S-1f59d479!Eldorado
AhnLab-V3Trojan/Win32.VBKrypt.R10081
McAfeeVBObfus.g
MAXmalware (ai score=87)
VBA32TScope.Trojan.VB
MalwarebytesGeneric.Malware.AI.DDS
PandaGeneric Malware
ZonerTrojan.Win32.147029
TrendMicro-HouseCallMal_VBNA-7
RisingWorm.Autorun!8.50 (TFE:3:MYn4tTpIzBI)
YandexTrojan.GenAsa!1Zt6lvffw2I
IkarusGen.Variant.Chinky
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.G!tr
BitDefenderThetaAI:Packer.996E32E320
AVGWin32:VB-ABDC [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan.Win.UnkAgent

How to remove Worm.Win32.Vobfus.efde?

Worm.Win32.Vobfus.efde removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment