Trojan

Trojan.Win32.Vobfus.xol removal tips

Malware Removal

The Trojan.Win32.Vobfus.xol is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Vobfus.xol virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Vobfus.xol?


File Info:

name: C1490FF36265CA1E50C3.mlw
path: /opt/CAPEv2/storage/binaries/02e5431314b210997eafde429e40a50cdcd588d708fa4ba668880ecdd635f3b6
crc32: 4188609D
md5: c1490ff36265ca1e50c3a9a6fa691c4d
sha1: fcf15207f0e279a9ab4401e762ae92065602620d
sha256: 02e5431314b210997eafde429e40a50cdcd588d708fa4ba668880ecdd635f3b6
sha512: 832e1e63fb1cc1ec30a4740145118cea9dc884311f4f23c76f7d459c0a417cf97291461d068ece39c168ae9973063d626acd2f4f255d6b530be6fc31511a2b0d
ssdeep: 6144:fXPwOBRtoITkA53pK122OWXHCmHZW50l7F9R6ew+O:fzBRtMcow2OWXH5HZW5qHRXO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B564F9162390FA1EE525CAF16B5D43A4953EEC3225D19807EBC03F2977B1E979232723
sha3_384: 89dae9bb3450a41a6289b01b7a542698cabd2ff0db279c5883116c01e04c07cb42ddce44147704857b85f27ed6d115f2
ep_bytes: 68cc4d4000e8eeffffff000000000000
timestamp: 2012-10-19 17:36:08

Version Info:

Translation: 0x0409 0x04b0
ProductName: Varanid
FileVersion: 2.50
ProductVersion: 2.50
InternalName: Hemotoxin
OriginalFilename: Hemotoxin.exe

Trojan.Win32.Vobfus.xol also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Vobfus.4!c
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner1.28472
MicroWorld-eScanGeneric.Dacic.DC06BB9F.A.CB3BA80C
ClamAVWin.Trojan.Changeup-6169544-0
CAT-QuickHealTrojan.Beebone.D
ALYacGeneric.Dacic.DC06BB9F.A.CB3BA80C
Cylanceunsafe
ZillyaTrojan.Vobfus.Win32.648741
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaMalware:Win32/km_2ffb6.None
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.7f0e27
BitDefenderThetaGen:NN.ZevbaF.36722.um0@aG0HCMci
VirITTrojan.Win32.VB2.AV
CyrenW32/Vobfus.BE.gen!Eldorado
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/VBObfus.CZ
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Vobfus.xol
BitDefenderGeneric.Dacic.DC06BB9F.A.CB3BA80C
NANO-AntivirusTrojan.Win32.WBNA.coonno
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-AETV [Trj]
TencentWorm.Win32.Vobfus.do
TACHYONTrojan/W32.Vobfus.327680
EmsisoftGeneric.Dacic.DC06BB9F.A.CB3BA80C (B)
F-SecureTrojan.TR/Barys.2644589
BaiduWin32.Worm.Pronny.d
VIPREGeneric.Dacic.DC06BB9F.A.CB3BA80C
TrendMicroWORM_VOBFUS.SMIV
McAfee-GW-EditionBehavesLike.Win32.VBObfus.fh
FireEyeGeneric.mg.c1490ff36265ca1e
SophosMal/SillyFDC-AC
IkarusWorm.Win32.Vobfus
GDataGeneric.Dacic.DC06BB9F.A.CB3BA80C
JiangminWorm/WBNA.dhje
WebrootW32.Obfuscated.Gen
AviraTR/Barys.2644589
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.ICOA@4r5x5p
ArcabitGeneric.Dacic.DC06BB9F.A.CB3BA80C
ZoneAlarmTrojan.Win32.Vobfus.xol
MicrosoftWorm:Win32/Vobfus.IB
GoogleDetected
AhnLab-V3Trojan/Win32.Menti.R40588
VBA32BScope.Trojan.Diple
MAXmalware (ai score=89)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMIV
RisingWorm.VobfusEx!1.99DF (CLOUD)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.4725823.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-AETV [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Vobfus.xol?

Trojan.Win32.Vobfus.xol removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment