Trojan

What is “Trojan.Win32.Vobfus.map”?

Malware Removal

The Trojan.Win32.Vobfus.map is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Vobfus.map virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Trojan.Win32.Vobfus.map?


File Info:

name: 2B996C63B4FBAEA0BDFA.mlw
path: /opt/CAPEv2/storage/binaries/452852b43a80ef3f2e4a6081be1f9a74e01e3380da7abf8d4b28143310153662
crc32: 5F4E1D4A
md5: 2b996c63b4fbaea0bdfaae533641b1e0
sha1: 4a1f7cec5f9ff098fbf1acf50a9982fc1847ce4e
sha256: 452852b43a80ef3f2e4a6081be1f9a74e01e3380da7abf8d4b28143310153662
sha512: d27c26dad110558661641a6ebe815de2630053e3b13fa5e137dd30a0cef235d3b18a0f86411839d889bad179d5169841332448675033209aa4aeeda5b8175f5d
ssdeep: 1536:jSHi0gNuTep4BNRXAEwqScgDz0Bg2PDXJRde/SwvFMYVwC+QaMaS+XjLlm:gfy4zDfDXJVI+fS+3s
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19FA3C67FB744809AD644A67036F7C3E6267778594F0B814B2288377B69A7F101E2CE53
sha3_384: 7ecac51137aa5a2c726dd26f1657a587d0d6b6ab26369eb69f1b01cd3454e75f380e97142b2108ce28f5dcd42308e94c
ep_bytes: 68b4124000e8eeffffff000000000000
timestamp: 2012-09-15 19:47:28

Version Info:

Translation: 0x0409 0x04b0
ProductName: Dematerialize
FileVersion: 7.33
ProductVersion: 7.33
InternalName: Traverso
OriginalFilename: Traverso.exe

Trojan.Win32.Vobfus.map also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.lC9L
tehtrisGeneric.Malware
DrWebWin32.HLLW.Autoruner1.26095
MicroWorld-eScanGen:Variant.Barys.2644
ClamAVWin.Trojan.Vobfus-16
FireEyeGeneric.mg.2b996c63b4fbaea0
CAT-QuickHealTrojan.Beebone.D
Cylanceunsafe
ZillyaTrojan.Vobfus.Win32.628135
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/vobfus.1030
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.3b4fba
BitDefenderThetaGen:NN.ZevbaF.36250.gm0@aeyP4Jpi
VirITTrojan.Win32.Zyx.NX
CyrenW32/Vobfus.AT.gen!Eldorado
SymantecW32.Changeup!gen20
Elasticmalicious (high confidence)
ESET-NOD32Win32/Pronny.EC
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Vobfus.map
BitDefenderGen:Variant.Barys.2644
NANO-AntivirusTrojan.Win32.Autoruner1.jvkfrw
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-AEMG [Trj]
TencentTrojan.Win32.Vobfus.hb
TACHYONTrojan/W32.Vobfus.102400.B
EmsisoftGen:Variant.Barys.2644 (B)
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Worm.Pronny.fs
VIPREGen:Variant.Barys.2644
TrendMicroWORM_VOBFUS.SM02
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-Y
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Barys.2644
JiangminTrojan/Vbobf.b
WebrootW32.Worm.Hw
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.Pronny.EB@4qtzpj
ArcabitTrojan.Barys.DA54
ZoneAlarmTrojan.Win32.Vobfus.map
MicrosoftWorm:Win32/Vobfus.HW
GoogleDetected
AhnLab-V3Trojan/Win32.Menti.R36560
McAfeeGenDownloader.rv
MAXmalware (ai score=86)
VBA32SScope.Malware-Cryptor.VBCR.3042
MalwarebytesPronny.Worm.Spreader.DDS
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SM02
RisingTrojan.Win32.VBCode.fvg (CLASSIC)
YandexTrojan.GenAsa!6fnUo41HIt0
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.4528063.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-AEMG [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Vobfus.map?

Trojan.Win32.Vobfus.map removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment