Trojan

What is “Trojan.Win32.Vobfus.hy”?

Malware Removal

The Trojan.Win32.Vobfus.hy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Vobfus.hy virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Trojan.Win32.Vobfus.hy?


File Info:

name: 03988446D4BE47DB901B.mlw
path: /opt/CAPEv2/storage/binaries/754b17be4bb94b62849859e4a536365ecb68a0b4479cad1bed4d34e67553e395
crc32: B27DBEC4
md5: 03988446d4be47db901bcd13789a5559
sha1: ec739076274b7eec45f0811e7a3d52d58e33a982
sha256: 754b17be4bb94b62849859e4a536365ecb68a0b4479cad1bed4d34e67553e395
sha512: 6afea2c46a249a7b841308f4bb89aa8ae8c4fe3256f4d71b3620f54e97c4c62b3bf7d28474ebe25934863a387c77063a16d38e4ab2960b98e653e31cd222a079
ssdeep: 1536:WubNEF69/67NxkiQixA+alh98r8Y9USv1jyWJFJwo7J:JbNEF69/67gjH8ri8HnwQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19AF3E6577B06404DD7543AB423EEC2D23792F4484F2B69C67AA4B1B4DCDAE211E34ACB
sha3_384: 3c6f0588662ddd6277d5bf9eae071caa5ca4ad7725ec67c3caeb25b8fa8fa7e1ac4fa727ab35bd5d515c5e9a9dca73fb
ep_bytes: 68a0124000e8f0ffffff000000000000
timestamp: 2001-02-27 23:41:40

Version Info:

0: [No Data]

Trojan.Win32.Vobfus.hy also known as:

BkavW32.InsuLateF.Trojan
LionicTrojan.Win32.Vobfus.lx2G
MicroWorld-eScanTrojan.GenericKDZ.96228
ClamAVWin.Trojan.Changeup-6169544-0
CAT-QuickHealTrojan.Beebone.D
McAfeeVBObfus.dv
MalwarebytesGeneric.Worm.AutoRun.DDS
ZillyaTrojan.Vobfus.Win32.615993
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
AlibabaWorm:Win32/vobfus.1030
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.6d4be4
BaiduWin32.Worm.Autorun.v
VirITTrojan.Win32.Zyx.JT
CyrenW32/Vobfus.AO.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.AUS
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Vobfus.hy
BitDefenderTrojan.GenericKDZ.96228
NANO-AntivirusTrojan.Win32.VB.rexdn
AvastWin32:GenMalicious-FAD [Trj]
TencentTrojan.Win32.Vobfus.ka
EmsisoftTrojan.GenericKDZ.96228 (B)
F-SecureTrojan.TR/Barys.629.jh.1
DrWebTrojan.Siggen4.7246
VIPRETrojan.GenericKDZ.96228
TrendMicroTROJ_GEN.R002C0CDM23
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cz
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.03988446d4be47db
SophosW32/SillyFDC-HV
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.96228
JiangminTrojan.Vobfus.zql
AviraTR/Barys.629.jh.1
MAXmalware (ai score=84)
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.VB.AUB@4ol77w
ArcabitTrojan.Generic.D177E4
ViRobotTrojan.Win32.A.VB.126976.W
ZoneAlarmTrojan.Win32.Vobfus.hy
MicrosoftWorm:Win32/Vobfus.EL
GoogleDetected
AhnLab-V3Trojan/Win.VB.R567073
Acronissuspicious
VBA32SScope.Malware-Cryptor.VBCR.1641
ALYacTrojan.GenericKDZ.96228
TACHYONTrojan/W32.VB-Vobfus.163840.B
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallTROJ_GEN.R002C0CDM23
RisingWorm.VobfusEx!1.99E1 (CLASSIC)
YandexTrojan.GenAsa!UUTN+wjiOFM
IkarusTrojan.Patched
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.AU!tr
BitDefenderThetaGen:NN.ZevbaF.36196.kmZ@a88RW3o
AVGWin32:GenMalicious-FAD [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Vobfus.hy?

Trojan.Win32.Vobfus.hy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment