Trojan

How to remove “Trojan:Win32/Vobfus”?

Malware Removal

The Trojan:Win32/Vobfus is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Vobfus virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Vobfus?


File Info:

crc32: 9E055ECD
md5: 46c8857ec21edf11fb58a060fb3ee022
name: 46C8857EC21EDF11FB58A060FB3EE022.mlw
sha1: 71a2b249e96888b6be55c4fd6e369a8f813d2f96
sha256: d439008b627de9cfb26595d48276ffce5e28dbc2c253d89a7957772139042401
sha512: 023071607bd14c1f9c0a1e23116d9680a548e01e8da8e8451563c0324813285b6140f62cf15f7a6b619722aa4628fb87cde953d4a3c291a21cd254314b7faa1c
ssdeep: 6144:awRwpRnynJqP6LqkEOwL8oLRBBxLAY1v4BS5xH1:a0F8L8oLvBxkYF4s5x
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018-2019
InternalName: Unistall
FileVersion: 1, 0, 0, 7
ProductName: x5378x8f7dx6e38x620f
ProductVersion: 1, 0, 0, 7
FileDescription: x5378x8f7dx7a0bx5e8f
OriginalFilename: Unistall.exe
Translation: 0x0804 0x04b0

Trojan:Win32/Vobfus also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.ESZU
FireEyeTrojan.Agent.ESZU
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeGenericR-NOS!46C8857EC21E
CylanceUnsafe
SangforTrojan.Win32.Save.a
BitDefenderTrojan.Agent.ESZU
Cybereasonmalicious.ec21ed
CyrenW32/S-ca1f0ff3!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/Vobfus.9072e58c
NANO-AntivirusTrojan.Win32.Dorifel.fnzlzs
RisingMalware.Undefined!8.C (RDMK:cmRtazqegpKigCIAYbmlcUglsi58)
Ad-AwareTrojan.Agent.ESZU
EmsisoftTrojan.Agent.ESZU (B)
ComodoTrojWare.Win32.TrojanDropper.Dorifel.F@846huk
F-SecureHeuristic.HEUR/AGEN.1109302
ZillyaDropper.Dorifel.Win32.20893
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
SophosML/PE-A
IkarusPUA.GameHack
JiangminTrojan.Generic.dsfva
AviraHEUR/AGEN.1109302
MAXmalware (ai score=82)
Antiy-AVLTrojan[Dropper]/Win32.Dorifel
MicrosoftTrojan:Win32/Vobfus
ArcabitTrojan.Agent.ESZU
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataWin32.Application.GameHack.S
CynetMalicious (score: 90)
AhnLab-V3Malware/Win32.Generic.C3054504
Acronissuspicious
ALYacTrojan.Agent.ESZU
VBA32BScope.TrojanDropper.Dorifel
MalwarebytesTrojan.Dropper
PandaTrj/GdSda.A
TencentWin32.Trojan-dropper.Dorifel.Peqa
YandexTrojan.GenAsa!/LEtCRFGwY4
MaxSecureTrojan.Malware.74157182.susgen
FortinetW32/Dorifel.BAHA!tr
BitDefenderThetaGen:NN.ZexaCO.34590.tu0@aecb6Ddj
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HgIASOgA

How to remove Trojan:Win32/Vobfus?

Trojan:Win32/Vobfus removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment