Worm

Worm.Win32.Vobfus.efva (file analysis)

Malware Removal

The Worm.Win32.Vobfus.efva is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.efva virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm.Win32.Vobfus.efva?


File Info:

name: A43262D62EC2FE63D49F.mlw
path: /opt/CAPEv2/storage/binaries/0d5ae8e09c529d09d187f0faa9625b829e62d2cdedf11ab48a61490dc99a8156
crc32: 30C21152
md5: a43262d62ec2fe63d49f0b80ea0fc64d
sha1: b3340e2de41def7797b2cb61ab680bd5c19c8fb0
sha256: 0d5ae8e09c529d09d187f0faa9625b829e62d2cdedf11ab48a61490dc99a8156
sha512: c936615d7faf96718de22df1f3cb451f390cf61df1ecfdc4e1bf87499ed643c96a086e3081ebb6a892f3df6aa025aa3ac2c394c69a6108d29375a1b64a23d97e
ssdeep: 3072:AUUeHPnuzh7sAFEouHwbBAW4hXNzcd6HFfak/K4jaU3bxt2SA:A99z/FEouH+BAi4HFfAgLGx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BE548321AB11617BF945C6F0682AAB66651C2E371BD5EC47B340BFA864712E3B1F070F
sha3_384: 45a22111fc13b622e5c14319aa824e5ad19e01c2436c653a0ae8d0be5305517d23d6029c9aaf1b76faeb5703c54467a5
ep_bytes: 68a0404000e8eeffffff000000000000
timestamp: 2012-03-05 18:46:26

Version Info:

Translation: 0x0409 0x04b0
ProductName: PIIKUDugG
FileVersion: 1.00
ProductVersion: 1.00
InternalName: QSxLeeTm
OriginalFilename: QSxLeeTm.exe

Worm.Win32.Vobfus.efva also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.95998
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.df
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.62ec2f
BitDefenderThetaGen:NN.ZevbaF.36802.sm0@aSK@PHbi
VirITTrojan.Win32.Zyx.IQ
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/AutoRun.VB.ASS
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMIH
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.efva
BitDefenderTrojan.GenericKDZ.95998
NANO-AntivirusTrojan.Win32.Vobfus.cydsbq
SUPERAntiSpywareTrojan.Agent/Gen-Vban
AvastWin32:AutoRun-CSL [Wrm]
TencentWorm.Win32.Vobfus.n
EmsisoftTrojan.GenericKDZ.95998 (B)
BaiduWin32.Worm.Autorun.l
F-SecureWorm.WORM/Vobfus.S.300
DrWebTrojan.VbCrypt.81
VIPRETrojan.GenericKDZ.95998
TrendMicroWORM_VOBFUS.SMIH
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.a43262d62ec2fe63
SophosMal/VBCheMan-B
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=80)
JiangminWorm/Vobfus.gim
GoogleDetected
AviraWORM/Vobfus.S.300
VaristW32/Vobfus.BE.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.995
MicrosoftWorm:Win32/Vobfus!pz
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Generic.D176FE
ZoneAlarmWorm.Win32.Vobfus.efva
GDataTrojan.GenericKDZ.95998
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VBKrypt.R22390
Acronissuspicious
VBA32Trojan.VB.01619
ALYacTrojan.GenericKDZ.95998
TACHYONWorm/W32.Vobfus.303104.B
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
RisingWorm.VobfusEx!1.99DC (CLASSIC)
YandexTrojan.GenAsa!w9h52XWjC88
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:AutoRun-CSL [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudWorm:Win/Vobfus.0542ce80

How to remove Worm.Win32.Vobfus.efva?

Worm.Win32.Vobfus.efva removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment