Worm

What is “Worm.Win32.Vobfus.efhl”?

Malware Removal

The Worm.Win32.Vobfus.efhl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.efhl virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm.Win32.Vobfus.efhl?


File Info:

name: 185102E81CE59227CF30.mlw
path: /opt/CAPEv2/storage/binaries/df1f97dec7bd5ed118ce7ca9c2169a5f4f06dac4e39cadb609acb4fca4d76b32
crc32: 1C65A40A
md5: 185102e81ce59227cf3056afd1715d6a
sha1: 27d75c7538389e418d5f29482cd19bb429e69705
sha256: df1f97dec7bd5ed118ce7ca9c2169a5f4f06dac4e39cadb609acb4fca4d76b32
sha512: 6a3e801f4f723daaa4751a58419969e4c4354f7d4c0dea35672bd4a01dd38827466becddc923fbc21c1d1f61873923aad0471c3ac8a7ae9816faacf6ad7e8ab3
ssdeep: 3072:su/jn/TZwR0V44ZeNeGVuLH/gefYMmsyvGdmo6aKqpaZ4oQZiEGz0Q:Z/KRakVu7/lfYfhGmTvWrQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15D0441126D80F23DF835C6F4292DD27054A59C762491A863FAC36EE972B2F67DD20327
sha3_384: d95ee5a23772fa33fbb3633a97adef414db6b663963287a583651f079ea163403544940c6c01563f1ccddb90eee5d587
ep_bytes: 68703f4000e8f0ffffff000000000000
timestamp: 2011-10-04 03:16:09

Version Info:

Translation: 0x0409 0x04b0
ProductName: azfmAYym
FileVersion: 1.00
ProductVersion: 1.00
InternalName: ZkEeUIoirP
OriginalFilename: ZkEeUIoirP.exe

Worm.Win32.Vobfus.efhl also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.VBKrypt.23
FireEyeGeneric.mg.185102e81ce59227
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.cm
ALYacGen:Variant.VBKrypt.23
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.VBKrypt.23
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan.Inject.n
VirITWorm.Win32.Generic.BAFU
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.ANA
APEXMalicious
ClamAVWin.Trojan.VB-1445
KasperskyWorm.Win32.Vobfus.efhl
BitDefenderGen:Variant.VBKrypt.23
NANO-AntivirusTrojan.Win32.VB.rilql
AvastWin32:VB-ABDC [Drp]
TencentTrojan.Win32.Koobface.p
EmsisoftGen:Variant.VBKrypt.23 (B)
F-SecureWorm.WORM/Vobfus.nasl
DrWebTrojan.VbCrypt.60
TrendMicroWORM_VOBFUS.SMHE
Trapminemalicious.moderate.ml.score
SophosMal/VB-XV
IkarusWorm.Win32.WBNA
GoogleDetected
AviraWORM/Vobfus.nasl
VaristW32/Vobfus.Z.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.VBKrypt.23
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
ZoneAlarmWorm.Win32.Vobfus.efhl
GDataGen:Variant.VBKrypt.23
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Diple.R13793
Acronissuspicious
BitDefenderThetaAI:Packer.C834D1051F
MAXmalware (ai score=85)
VBA32BScope.Worm.Vobfus
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMHE
RisingWorm.Vobfus!1.99C7 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.CNE!worm
AVGWin32:VB-ABDC [Drp]
Cybereasonmalicious.81ce59
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.5932f0fd

How to remove Worm.Win32.Vobfus.efhl?

Worm.Win32.Vobfus.efhl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment