Worm

Worm.Win32.Vobfus.erbm information

Malware Removal

The Worm.Win32.Vobfus.erbm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.erbm virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm.Win32.Vobfus.erbm?


File Info:

name: 95B6DC75A342DEA90D94.mlw
path: /opt/CAPEv2/storage/binaries/b376df62da041c7bc6fbb5d69c0a0f843dd959bec81d153de0d7fa46d739a55d
crc32: 539509CB
md5: 95b6dc75a342dea90d94d6d8390c85a9
sha1: b3c981dad02db195c4dbe0e6174191bffa7d8ec4
sha256: b376df62da041c7bc6fbb5d69c0a0f843dd959bec81d153de0d7fa46d739a55d
sha512: 5134ef27820437846870e9a0c446bdd28163e23fefd719417ce2dc29f9daab0ba8c117d831da2b3f9e30e865f66997de320c8541d75767ee55def5ecdb80a7b6
ssdeep: 6144:GjyYIFdn53qLowKnvmb7/D26NID5UR2uNhVc5QTI/MfqZN:G29n53qLowKnvmb7/D26rVc5AIMfqZN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B124B612FA01B41BF18698F05A6E8756382D2D7E26D0AC07B781BF5766705A7B8F031F
sha3_384: a18e664fe1205fb7d1b43326a7d302698ae068f1b295619dd28d47c9d45cf930302fa3cdbeb79e700dde47d4b3c4d46e
ep_bytes: 68243d4000e8eeffffff000000000000
timestamp: 2011-11-15 06:55:43

Version Info:

ProductName:
FileVersion: 1.00
ProductVersion: 1.00
InternalName:
OriginalFilename:

Worm.Win32.Vobfus.erbm also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lIOe
tehtrisGeneric.Malware
DrWebTrojan.VbCrypt.77
MicroWorld-eScanGen:Variant.VBInject.11
ClamAVWin.Trojan.Diple-8426
FireEyeGeneric.mg.95b6dc75a342dea9
CAT-QuickHealWorm.VobfusVMF.S20100119
ALYacGen:Variant.VBInject.11
Cylanceunsafe
VIPREGen:Variant.VBInject.11
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/Vobfus.85a69509
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderThetaGen:NN.ZevbaF.36250.om0@aG1Hh5di
VirITTrojan.Win32.Generic.CCEE
CyrenW32/Vobfus.Z.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.APF
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.erbm
BitDefenderGen:Variant.VBInject.11
NANO-AntivirusTrojan.Win32.WBNA.csfhek
SUPERAntiSpywareTrojan.Agent/Gen-Autogen
AvastWin32:Evo-gen [Trj]
RisingWorm.VobfusEx!1.99DC (CLASSIC)
TACHYONWorm/W32.Vobfus.229376.E
SophosMal/Generic-R
F-SecureTrojan.TR/VB.Inject.112561
BaiduWin32.Worm.Autorun.l
ZillyaWorm.WBNAGen.Win32.12
TrendMicroWORM_VOBFUS.SMAB
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dm
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.VBInject.11 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Diple.Gen
AviraTR/VB.Inject.112561
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.VBInject.11
ZoneAlarmWorm.Win32.Vobfus.erbm
GDataGen:Variant.VBInject.11
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R16322
Acronissuspicious
McAfeeVBObfus.cm
MAXmalware (ai score=85)
VBA32BScope.TrojanRansom.Blocker
MalwarebytesGeneric.Worm.AutoRun.DDS
PandaTrj/Spyeye.C
TrendMicro-HouseCallWORM_VOBFUS.SMAB
TencentWorm.Win32.Vobfus.n
YandexTrojan.GenAsa!QzBPxRjx8PM
IkarusTrojan.Win32.Diple
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Diple.ZMH2!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.5a342d
DeepInstinctMALICIOUS

How to remove Worm.Win32.Vobfus.erbm?

Worm.Win32.Vobfus.erbm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment