Worm

Worm.Win32.Vobfus.efmk removal instruction

Malware Removal

The Worm.Win32.Vobfus.efmk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.efmk virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.Vobfus.efmk?


File Info:

name: 448516F3F8D68C2543BF.mlw
path: /opt/CAPEv2/storage/binaries/f320b930b1cfa96bbda701b7f0f3dc8ce54479afe6fd056806c2a431bcc98562
crc32: CDCAB30E
md5: 448516f3f8d68c2543bf56398bbf92c0
sha1: 60341504b48e1c992feb6198034a8a6c37fe2ae9
sha256: f320b930b1cfa96bbda701b7f0f3dc8ce54479afe6fd056806c2a431bcc98562
sha512: 3aa65589a437d5082f29c1cfb68cd2dd2ed4fa0db5e04f9a001f3811cbca1e19a2fc96f51db88a6e76d7e3c09b4c94d8ade733ac0edc1a0709afb8fdf9a66b55
ssdeep: 3072:BhhxJptfKqOdBsebgeDyJiqmdoTtawZPotUPvPDspYxjatL0JiTeDXokR49M6e3+:vhDptfKRLsebgeDyJtmdo7PIWDspYJaV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T193F3832936C1F73ED815C6F43D69C290A47AEC3225E16807F7C26B1676B1E6BD220763
sha3_384: 3b8a49b7aa4c1a29b7370344af3d85ab500bd9c789804054ba057f74e0e3093fe4df557aea892010c960b749b7e8bacd
ep_bytes: 6880354000e8f0ffffff000000000000
timestamp: 2011-09-21 03:11:54

Version Info:

Translation: 0x0409 0x04b0
ProductName: CuAHHjmo
FileVersion: 1.00
ProductVersion: 1.00
InternalName: GaydyNZTEHsANwNf
OriginalFilename: GaydyNZTEHsANwNf.exe

Worm.Win32.Vobfus.efmk also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Conjar.1
FireEyeGeneric.mg.448516f3f8d68c25
CAT-QuickHealTrojan.Vobfus.gen
McAfeeVBObfus.bn
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.4b48e1
ArcabitTrojan.Conjar.1
BitDefenderThetaAI:Packer.E4CCBB8E20
VirITTrojan.Win32.VBKrypt.GUAV
CyrenW32/Vobfus.Z.gen!Eldorado
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/AutoRun.VB.ALW
TrendMicro-HouseCallWORM_VOBFUS.SMAC
AvastWin32:VB-YLZ [Trj]
ClamAVWin.Trojan.VB-1559
KasperskyWorm.Win32.Vobfus.efmk
BitDefenderGen:Heur.Conjar.1
NANO-AntivirusTrojan.Win32.WBNA.covlqs
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
TencentTrojan.Win32.Koobface.p
TACHYONTrojan/W32.VB-VBKrypt.163840.Z
SophosMal/VB-XV
BaiduWin32.Worm.Pronny.d
F-SecureTrojan.TR/Spy.Agent.163848
DrWebTrojan.VbCrypt.60
VIPREGen:Heur.Conjar.1
TrendMicroWORM_VOBFUS.SMAC
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.high.ml.score
EmsisoftGen:Heur.Conjar.1 (B)
WebrootW32.Trojan.Diple.Gen
GoogleDetected
AviraTR/Spy.Agent.163848
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.VB.AVA@4paxk7
MicrosoftWorm:Win32/Vobfus.DI
ZoneAlarmWorm.Win32.Vobfus.efmk
GDataGen:Heur.Conjar.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Diple.R13793
Acronissuspicious
VBA32BScope.Trojan.VB.Diple.01583
MAXmalware (ai score=86)
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
APEXMalicious
RisingWorm.Vobfus!1.99C7 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VB.CNE!worm
AVGWin32:VB-YLZ [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm.Win32.Vobfus.efmk?

Worm.Win32.Vobfus.efmk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment