Worm

Worm.Win32.Vobfus.efgc (file analysis)

Malware Removal

The Worm.Win32.Vobfus.efgc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.efgc virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm.Win32.Vobfus.efgc?


File Info:

name: 8BFCCEB4A0C52AA52FAE.mlw
path: /opt/CAPEv2/storage/binaries/9d087f000234563c785b077885e192aa2f23623f2ee91a232039a5a6504994ae
crc32: 2C792C60
md5: 8bfcceb4a0c52aa52faec8314a5cdc85
sha1: d3e8725847c80ef2071a1130f01ab655929dc296
sha256: 9d087f000234563c785b077885e192aa2f23623f2ee91a232039a5a6504994ae
sha512: 1b359e79ea1be8946d3cf6459be7601e9c4c65f70d2b94ace13695b2145fa3e6eeb37eb33fc14115ae7be544db89f9004300df043317f49697dfdbcdced272fc
ssdeep: 3072:9nnbW+ZO37RQNN+4+8taCCKh5yo8cFHbL1+ik5gDE5j4oQe:FW+07cNx+8FCKDxN1xk57d
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FFE3842A73A0F77EC825C6F83D1982A4A039ED3525E26C13F6C26F5A76B1D57D220353
sha3_384: ab28395349d0232026a8447952d719532f01be86fe070ba5249cd90e9446370749a01afb715bce5a0a4cc2f44d85ca9f
ep_bytes: 68b4334000e8eeffffff000000000000
timestamp: 2011-09-20 13:08:04

Version Info:

Translation: 0x0409 0x04b0
ProductName: BhPEGLOzTBEdvHNhGj
FileVersion: 1.00
ProductVersion: 1.00
InternalName: JazLHfgw
OriginalFilename: JazLHfgw.exe

Worm.Win32.Vobfus.efgc also known as:

BkavW32.AIDetectMalware
AVGWin32:VB-ABDC [Drp]
MicroWorld-eScanGen:Variant.Barys.2424
FireEyeGeneric.mg.8bfcceb4a0c52aa5
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeVBObfus.bn
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Barys.2424
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.4a0c52
BitDefenderThetaAI:Packer.33CBDA9D20
VirITWorm.Win32.VBNA.AWOU
SymantecW32.Changeup!gen35
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.ALW
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:VB-ABDC [Drp]
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.efgc
BitDefenderGen:Variant.Barys.2424
NANO-AntivirusTrojan.Win32.WBNA.covknc
SUPERAntiSpywareTrojan.Agent/Gen-FakeAV
TencentTrojan.Win32.Koobface.p
SophosMal/VB-XV
BaiduWin32.Trojan.Inject.n
F-SecureTrojan.TR/Spy.Agent.155646
DrWebTrojan.VbCrypt.60
TrendMicroWORM_VOBFUS.SMHE
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Barys.2424 (B)
SentinelOneStatic AI – Malicious PE
VaristW32/Vobfus.V.gen!Eldorado
AviraTR/Spy.Agent.155646
MAXmalware (ai score=85)
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumWorm.Win32.VB.AB@4pji3v
ArcabitTrojan.Barys.D978
ZoneAlarmWorm.Win32.Vobfus.efgc
GDataGen:Variant.Barys.2424
GoogleDetected
AhnLab-V3Trojan/Win32.Diple.R13793
Acronissuspicious
VBA32BScope.Trojan.VB.Diple.01583
ALYacGen:Variant.Barys.2424
TACHYONWorm/W32.VB-VBNA.155648.C
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMHE
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!EkypYBGvYQI
IkarusTrojan.Spy.Agent
FortinetW32/VB.CNE!worm
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan[spy]:Win/Barys.df0e955b

How to remove Worm.Win32.Vobfus.efgc?

Worm.Win32.Vobfus.efgc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment