Worm

How to remove “Worm.Win32.Vobfus.eryt”?

Malware Removal

The Worm.Win32.Vobfus.eryt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.eryt virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.Vobfus.eryt?


File Info:

name: 73E58549AD9B6970AF7D.mlw
path: /opt/CAPEv2/storage/binaries/ef670edab2209edce07198c7898d1329b44b470113665b56273e39946b1c340d
crc32: 55DCA942
md5: 73e58549ad9b6970af7d40dfd5769fb2
sha1: 0199c77615fade9d90daca069cbee02289f161ce
sha256: ef670edab2209edce07198c7898d1329b44b470113665b56273e39946b1c340d
sha512: 0632d6624c3bb316657e430b9af0a2a6e957c479d12eb48f6d6b38a584bac53001f66981563c39cdf92f4fa42108db37ec2927b347a38eaf84bc58be54960eef
ssdeep: 3072:SBd1vE2MtU7Qv0w4ZRRQMMDwtIMCeFP4ANV4oQZiEXx:wdlE2R7Qvb4tQTaCeFP4ABWb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T140F3A42A7681F23ED425CAF5382A83A0947EEC3625D66C17F7C11B15B2F1DABD220753
sha3_384: a7a923393c49d1dbdabb7272b29761d8172b980f98e6ebcb2a7d5953244dc38097148208aecf7a5ca022a1849b56f507
ep_bytes: 6868394000e8eeffffff000000000000
timestamp: 2000-01-10 01:33:18

Version Info:

Translation: 0x0409 0x04b0
ProductName: YAzZgthXiU
FileVersion: 1.00
ProductVersion: 1.00
InternalName: qlcwIOpOwb
OriginalFilename: qlcwIOpOwb.exe

Worm.Win32.Vobfus.eryt also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.low6
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeVBObfus.bn
Cylanceunsafe
VIPREGen:Trojan.Sresmon.Gen.1
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Vobfus.849c6a82
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Worm.Pronny.d
VirITWorm.Win32.VBNA.AWAG
SymantecW32.Changeup!gen35
tehtrisGeneric.Malware
ESET-NOD32Win32/Pronny.AC
ZonerTrojan.Win32.88040
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.eryt
BitDefenderGen:Trojan.Sresmon.Gen.1
NANO-AntivirusTrojan.Win32.VB.ccdabr
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
MicroWorld-eScanGen:Trojan.Sresmon.Gen.1
AvastWin32:VB-ABDC [Drp]
TencentTrojan.Win32.Koobface.p
TACHYONWorm/W32.Vobfus.159744.L
EmsisoftGen:Trojan.Sresmon.Gen.1 (B)
F-SecureWorm.WORM/VB.jla
DrWebTrojan.VbCrypt.60
TrendMicroWORM_VOBFUS.SMAC
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.73e58549ad9b6970
SophosMal/VB-XV
IkarusWorm.Win32.WBNA
GDataGen:Trojan.Sresmon.Gen.1
VaristW32/Vobfus.V.gen!Eldorado
AviraWORM/VB.jla
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Sresmon.Gen.1
ZoneAlarmWorm.Win32.Vobfus.eryt
MicrosoftWorm:Win32/VB.JL
GoogleDetected
AhnLab-V3Trojan/Win32.Diple.R13793
Acronissuspicious
VBA32Malware-Cryptor.VB.gen
MAXmalware (ai score=80)
MalwarebytesGeneric.Malware.AI.DDS
PandaGeneric Malware
TrendMicro-HouseCallWORM_VOBFUS.SMAC
RisingWorm.Vobfus!1.99C7 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
BitDefenderThetaAI:Packer.2EAE27BF1F
AVGWin32:VB-ABDC [Drp]
Cybereasonmalicious.9ad9b6
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.671a95ca

How to remove Worm.Win32.Vobfus.eryt?

Worm.Win32.Vobfus.eryt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment