Worm

Worm.Win32.Vobfus.ela (file analysis)

Malware Removal

The Worm.Win32.Vobfus.ela is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.ela virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.Vobfus.ela?


File Info:

name: F473194689DC77781278.mlw
path: /opt/CAPEv2/storage/binaries/92cf08fcfe241b05f2708b601fe57e94283fcbdb8dddfa9882c4e71f16738050
crc32: 6384B1D0
md5: f473194689dc77781278304c26cc79fc
sha1: 8766a8bf766b9183590217e99b90c575d5dd72c7
sha256: 92cf08fcfe241b05f2708b601fe57e94283fcbdb8dddfa9882c4e71f16738050
sha512: 15608d14ef77f10865326eeb41ab2dc9ea81d93b5152ba938110c9703ef4e51aee7fd73d6186d7d94a7e88b527e5b03f03f3bbb0b515f04db2f2085b7a618891
ssdeep: 3072:Du1zrbPFBTZCchor5KFjvFP5YCkyJnnrr:6NF7ha5KFjNcaH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T173F3093ABA86899DD759167028E7C7F213B3741A5F07490F3688376A2CB1F342E59B43
sha3_384: 1db065e0e25550ac0af3df53a09ed2b1f23289e997f20a8582d54bf5d248fd45ebd0db6dbca664eadc264e9dd74f5d7d
ep_bytes: 68d4174000e8f0ffffff000050000000
timestamp: 2012-09-21 17:27:19

Version Info:

Translation: 0x0409 0x04b0
ProductName: radiasti
FileVersion: 4.03
ProductVersion: 4.03
InternalName: wreathe
OriginalFilename: wreathe.exe

Worm.Win32.Vobfus.ela also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.VbCrypt.81
MicroWorld-eScanTrojan.GenericKDZ.96073
CAT-QuickHealWorm.VobfusMF.S27266072
ALYacTrojan.GenericKDZ.96073
MalwarebytesPronny.Worm.Spreader.DDS
VIPRETrojan.GenericKDZ.96073
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 005640b91 )
K7GWTrojan ( 005640b91 )
Cybereasonmalicious.689dc7
BitDefenderThetaGen:NN.ZevbaF.36250.km0@aObeXSfi
VirITTrojan.Win32.Generic.CELD
CyrenW32/VB.HE.gen!Eldorado
SymantecW32.Changeup
ESET-NOD32Win32/Pronny.EL
APEXMalicious
ClamAVWin.Trojan.Pronny-2
KasperskyWorm.Win32.Vobfus.ela
BitDefenderTrojan.GenericKDZ.96073
NANO-AntivirusTrojan.Win32.Vobfus.eodmcn
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-AENM [Trj]
RisingTrojan.VB!1.99F7 (CLASSIC)
EmsisoftTrojan.GenericKDZ.96073 (B)
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Worm.Pronny.gi
TrendMicroWORM_VOBFUS.SM02
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.f473194689dc7778
SophosMal/SillyFDC-Y
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.VB.SE
JiangminWorm.Vobfus.bni
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=84)
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.ABQ@4puwz1
ArcabitTrojan.Generic.D17749
ViRobotWorm.Win32.A.Vobfus.172032
ZoneAlarmWorm.Win32.Vobfus.ela
MicrosoftWorm:Win32/Vobfus.IE
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Vobfus.R38810
McAfeeVBObfus.dv
TACHYONWorm/W32.Vobfus.172032.B
VBA32Worm.Vobfus
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM02
TencentWorm.Win32.Vobfus.q
YandexTrojan.GenAsa!AWbSy/YbgE4
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.4564723.susgen
FortinetW32/Diple.EJQE!tr
AVGWin32:VB-AENM [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm.Win32.Vobfus.ela?

Worm.Win32.Vobfus.ela removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment