Worm

Worm.Win32.Vobfus.efrl (file analysis)

Malware Removal

The Worm.Win32.Vobfus.efrl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.efrl virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.Vobfus.efrl?


File Info:

name: 79A2034E22E7C7C10ABE.mlw
path: /opt/CAPEv2/storage/binaries/e0dce3c0757910a282247ab57d49f09254485115b44ed84f00b13a461a36c9ab
crc32: 89F47F90
md5: 79a2034e22e7c7c10abe2f80e937ee1a
sha1: ebb4603c84f426b861a200969278b1eb17a9f2e8
sha256: e0dce3c0757910a282247ab57d49f09254485115b44ed84f00b13a461a36c9ab
sha512: 3a6212e25f712c33d34db918064fbee9b07102468cee6e93e28f950baddcdcd0a658cde4c8a1c44c905b3b0d8ea8f917a27b0883ebe59d58e9e0075e6a449335
ssdeep: 6144:mLFL9GKI//d8xgN3+E9xz3DfQr1w2O6EU02DPp9nrg5G35aJevhRGGhfZkEscw0V:op7g9+EDEnhtHAJevHsEscw0LcLW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T133640149AD1C7039F88688735C269357680D1E371A80FC6FB381AB4971B569BB6F432F
sha3_384: 8adea417312df624ea4c4ca286f3cd6c766f60be3dcd13b65d97fa09793c16779f4c451d682f02b23c306a514c176ada
ep_bytes: 6820444000e8f0ffffff000000000000
timestamp: 2012-03-21 04:01:35

Version Info:

ProductName:
FileVersion: 1.00
ProductVersion: 1.00
InternalName:
OriginalFilename:
Translation: 0x0409 0x04b0

Worm.Win32.Vobfus.efrl also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Vobfus.o!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.950
FireEyeGeneric.mg.79a2034e22e7c7c1
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.fm
McAfeeVBObfus.dh
MalwarebytesPronny.Worm.Spreader.DDS
VIPREGen:Variant.Barys.950
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Vobfus.7da5a957
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Worm.Autorun.l
VirITTrojan.Win32.SHeur4.VPI
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.ATQ
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMJA
ClamAVWin.Trojan.Otran-3
KasperskyWorm.Win32.Vobfus.efrl
BitDefenderGen:Variant.Barys.950
NANO-AntivirusTrojan.Win32.Jorik.covkca
SUPERAntiSpywareTrojan.Agent/Gen-Remnat[VB]
AvastWin32:VB-ABUX [Trj]
TencentTrojan.Win32.FakeFolder.gcp
EmsisoftGen:Variant.Barys.950 (B)
F-SecureTrojan.TR/VBInject.11.A.1
DrWebTrojan.VbCrypt.60
TrendMicroWORM_VOBFUS.SMJA
Trapminemalicious.moderate.ml.score
SophosW32/SillyFDC-HS
IkarusWorm.Win32.Vobfus
MAXmalware (ai score=88)
GoogleDetected
AviraTR/VBInject.11.A.1
VaristW32/VBcrypt.T.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Barys.950
ZoneAlarmWorm.Win32.Vobfus.efrl
GDataGen:Variant.Barys.950
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R22659
Acronissuspicious
BitDefenderThetaAI:Packer.CB1EFD2920
ALYacGen:Variant.Barys.950
TACHYONWorm/W32.Vobfus.327680.E
VBA32BScope.Trojan.VB.Onechki
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!dFlQiwYYslQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-ABUX [Trj]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.f62ce64a

How to remove Worm.Win32.Vobfus.efrl?

Worm.Win32.Vobfus.efrl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment