Worm

What is “Worm.Win32.Vobfus.efpg”?

Malware Removal

The Worm.Win32.Vobfus.efpg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.efpg virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm.Win32.Vobfus.efpg?


File Info:

name: 67EF598F4D930DD03A9E.mlw
path: /opt/CAPEv2/storage/binaries/48b0b8ff735159da31e82fce77b85eaacd48ec4d864559990cc47b011bbf7bfc
crc32: AA06542D
md5: 67ef598f4d930dd03a9e42d82408c63c
sha1: 2f9c29bcb4d95993fc2123e2caa7dbf8ee14293a
sha256: 48b0b8ff735159da31e82fce77b85eaacd48ec4d864559990cc47b011bbf7bfc
sha512: 92893efeefdd311aafac80e5c72b5a6b3b0da3816b6d6800b04b39310589dc8eacbd4b9537699831fbbabe14d4e0fa69ddcb828c2b63696adb008eb8b87170ef
ssdeep: 1536:3wWp7gYu9+7gWbrimfWSeJFzkRcTwdEQdIumgDL0FfxTGCpim4jSJ:3w1T8gWi2eJFzkRswUumgDLOfviOJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15ED3B41A36A1E13AC615CAF42D5A83E080BDAD3635D2AD17F7C21B16B7F2DA78350713
sha3_384: 58e88cdab627f3e100c4cf89aaccc67954f94b1d8c37bec87bcb6a470c110b7293c41f14f386ad1b31b36ffebc05062b
ep_bytes: 68b0334000e8f0ffffff000000000000
timestamp: 2011-08-23 00:58:23

Version Info:

Translation: 0x0409 0x04b0
ProductName: xXERCIFiTnub
FileVersion: 1.00
ProductVersion: 1.00
InternalName: ftyBxCBqIO
OriginalFilename: ftyBxCBqIO.exe

Worm.Win32.Vobfus.efpg also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.2490
FireEyeGeneric.mg.67ef598f4d930dd0
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.cm
ALYacGen:Variant.Barys.2490
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaMalware:Win32/km_2ff8.None
K7GWEmailWorm ( 0054d10f1 )
BitDefenderThetaAI:Packer.790A8FDE20
VirITTrojan.Win32.Diple.ALFA
SymantecW32.Changeup!gen35
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.AKF
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.efpg
BitDefenderGen:Variant.Barys.2490
NANO-AntivirusTrojan.Win32.VB.rilqp
SUPERAntiSpywareTrojan.Agent/Gen-FakeAlert[Dropper]
AvastWin32:Regrun-II [Trj]
TencentWorm.Win32.Vobfus.n
TACHYONTrojan/W32.Agent.135168.B
EmsisoftGen:Variant.Barys.2490 (B)
BaiduWin32.Worm.Pronny.d
F-SecureTrojan.TR/Spy.Agent.135173
DrWebTrojan.VbCrypt.60
VIPREGen:Variant.Barys.2490
TrendMicroWORM_VOBFUS.SMAC
Trapminemalicious.high.ml.score
SophosMal/VB-XV
SentinelOneStatic AI – Malicious PE
JiangminWorm.Vobfus.lspw
GoogleDetected
AviraTR/Spy.Agent.135173
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.Vobfus.~s@4m2ayb
ArcabitTrojan.Barys.D9BA
ZoneAlarmWorm.Win32.Vobfus.efpg
GDataWin32.Trojan.PSE.10I69CR
VaristW32/Vobfus.V.gen!Eldorado
AhnLab-V3Trojan/Win32.Diple.R23097
Acronissuspicious
McAfeeVBObfus.df
MAXmalware (ai score=83)
VBA32Trojan.VB.01507
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMAC
RisingWorm.Vobfus!1.99C8 (CLASSIC)
YandexTrojan.GenAsa!AgAC35TxNOA
IkarusTrojan.Win32.Diple
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:Regrun-II [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Vobfus.3acba3fb

How to remove Worm.Win32.Vobfus.efpg?

Worm.Win32.Vobfus.efpg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment