Worm

Worm.Win32.Vobfus.eflw removal instruction

Malware Removal

The Worm.Win32.Vobfus.eflw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.eflw virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm.Win32.Vobfus.eflw?


File Info:

name: C4522161CDB9D834A00A.mlw
path: /opt/CAPEv2/storage/binaries/f71b28b0858230cc34a677a9c780d2a1f37afc68b60bbb1e0dea684730b25c9a
crc32: D73E8A93
md5: c4522161cdb9d834a00af816ca339776
sha1: f3e02c542ed616eead25f88e14a7b1f111cd3053
sha256: f71b28b0858230cc34a677a9c780d2a1f37afc68b60bbb1e0dea684730b25c9a
sha512: 6b90b11ee66bce1d9bbf251b3ef4722b5a880507f73c9812cc593681e9fe9f1ba21554ddc1d9caf2702995f1024bd884f469eee74530212ca5acb091c3cf6b99
ssdeep: 6144:C9Rww39SfGzlTphJgW9mnrQLMjTsZzILK/fObT/bGiuF0a59ONKLUWrlhO1a8p5q:/w39SfGzlTPJgWUnjjTsZzILK/fObT/6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FD34C813BA10F01AE693D4F029299396782A2D792690FC5773827F2965711D7B8F370F
sha3_384: c014403e887aec2891d630247121ad32f9dd091062dcbbb20a94e596083051409f41faa54a7b27ee77fd7864fe53bd4b
ep_bytes: 6858404000e8eeffffff000040000000
timestamp: 2011-12-26 05:20:30

Version Info:

FileVersion: 1.00
Translation: 0x0409 0x04b0

Worm.Win32.Vobfus.eflw also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.VBInject.11
ClamAVWin.Trojan.Changeup-6169544-0
FireEyeGeneric.mg.c4522161cdb9d834
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.er
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.VBInject.11
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Worm.Autorun.l
VirITWorm.Win32.Generic.BGDH
SymantecW32.Changeup!gen15
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.AQE
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.eflw
BitDefenderGen:Variant.VBInject.11
NANO-AntivirusTrojan.Win32.Vobfus.dwtlbd
AvastWin32:VB-AALQ [Trj]
TencentTrojan.Win32.FakeFolder.pid
TACHYONWorm/W32.Vobfus.249856.G
EmsisoftGen:Variant.VBInject.11 (B)
F-SecureTrojan.TR/Kazy.502562
DrWebTrojan.VbCrypt.81
TrendMicroWORM_VOBFUS.SMAB
SophosML/PE-A
IkarusTrojan.Win32.Diple
GDataGen:Variant.VBInject.11
GoogleDetected
AviraTR/Kazy.502562
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.VBInject.11
ViRobotTrojan.Win32.A.Diple.249856.E
ZoneAlarmWorm.Win32.Vobfus.eflw
MicrosoftWorm:Win32/Vobfus.CF
VaristW32/Vobfus.AA.gen!Eldorado
AhnLab-V3Trojan/Win32.Menti.R18663
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36802.pm0@aey2lVai
ALYacGen:Variant.VBInject.11
MAXmalware (ai score=82)
VBA32BScope.Trojan.Diple
Cylanceunsafe
TrendMicro-HouseCallWORM_VOBFUS.SMAB
RisingWorm.VobfusEx!1.99DC (CLASSIC)
YandexTrojan.GenAsa!ZC3WiTHvx7U
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Diple.EJQE!tr
AVGWin32:VB-AALQ [Trj]
Cybereasonmalicious.1cdb9d
PandaTrj/Genetic.gen
alibabacloudTrojan:Win/Vobfus.856fdbba

How to remove Worm.Win32.Vobfus.eflw?

Worm.Win32.Vobfus.eflw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment