Malware

VBS/Obfuscated.G removal instruction

Malware Removal

The VBS/Obfuscated.G is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VBS/Obfuscated.G virus can do?

  • Injection (inter-process)
  • At least one process apparently crashed during execution
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

How to determine VBS/Obfuscated.G?


File Info:

crc32: D529DC82
md5: e23990a725096d568e9484d732ae7726
name: E23990A725096D568E9484D732AE7726.mlw
sha1: 38b34ab3400ff05fbaf7f452db2339cf4dc091fe
sha256: a5c4264a541c848bb33de3bcfb1c493b2cacad2e9b0e5075da87c2d50b0d5175
sha512: ab3b8db9ba39c42bbfa9036889244a1e249c0e4683fcc1a5af825129de1fa3fa57cfa067e45be073d22cf444a6369ded33883c25d6164bc649bcc7a5c70b19aa
ssdeep: 1536:WKDqJvz2xyM40DSmJDVMdqEm72V+R5eYORB:WKDAfCDSmJ2mg+CBf
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

VBS/Obfuscated.G also known as:

K7AntiVirusTrojan ( 004d2dcc1 )
DrWebBackDoor.Siggen.60475
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.2888985
CylanceUnsafe
SangforMalware.Generic-Script.Save.5864a21c
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:VBS/Blocker.c1f6e1a3
K7GWTrojan ( 004d2dcc1 )
Cybereasonmalicious.725096
BaiduVBS.Trojan.Obfuscated.ae
CyrenVBS/Agent.HE
SymantecTrojan.Gen
ESET-NOD32VBS/Obfuscated.G
APEXMalicious
AvastScript:SNH-gen [Trj]
KasperskyTrojan-Ransom.Win32.Blocker.hsyz
BitDefenderTrojan.GenericKD.2888985
NANO-AntivirusTrojan.Script.ExpKit.exylvw
MicroWorld-eScanTrojan.GenericKD.2888985
TencentWin32.Trojan.Blocker.Ahef
Ad-AwareTrojan.GenericKD.2888985
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionVBS/Downloader.gy
FireEyeTrojan.GenericKD.2888985
EmsisoftTrojan.GenericKD.2888985 (B)
WebrootW32.Malware.Ml.Vt
AviraWORM/Jenxcus.77295
MicrosoftTrojan:Win32/Ditertag.A
ZoneAlarmTrojan-Ransom.Win32.Blocker.hsyz
GDataTrojan.GenericKD.2888985
McAfeeArtemis!E23990A72509
MAXmalware (ai score=86)
VBA32Hoax.Blocker
PandaTrj/CI.A
IkarusTrojan.VBS.Agent
FortinetVBS/Agent.XT!tr
AVGScript:SNH-gen [Trj]
Paloaltogeneric.ml

How to remove VBS/Obfuscated.G?

VBS/Obfuscated.G removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment