Worm

Worm.Win32.Vobfus.eryt (file analysis)

Malware Removal

The Worm.Win32.Vobfus.eryt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.eryt virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.Vobfus.eryt?


File Info:

name: 1EB06A16F1DA1C354A56.mlw
path: /opt/CAPEv2/storage/binaries/aa29425592bdf7d88da26adb27774a5ff936f80f720585f119043fb5ae995347
crc32: 70F2BA4E
md5: 1eb06a16f1da1c354a56157fdb358c69
sha1: c60285ac231005f5e0dc551622d25e08a1410b78
sha256: aa29425592bdf7d88da26adb27774a5ff936f80f720585f119043fb5ae995347
sha512: 98c2c8294458d884ce716ad3d8a8b03e09709a3b3656feb1f2bcf18d10ab897759cc549cc5d0ddd94ef57eeab96b8981497dae41559ec57c68878a87d8690ffc
ssdeep: 3072:SBd1NE2MtU7Qv0w4ZRRQMMDwtIMCeFP4ANV4oQZiEQ3QT:wdrE2R7Qvb4tQTaCeFP4ABWO3k
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T157F3942A7680F23ED425CAF5382A43A0947EEC3625D66C17F7C11B16B6F1DABD220753
sha3_384: 13784534c4d6c83a84e59f0fab9073fb6308e7c6a506328fbadeae32ee782fcf74150a537981d62a8cb0d204479494f9
ep_bytes: 6868394000e8eeffffff000000000000
timestamp: 2000-01-10 01:33:18

Version Info:

Translation: 0x0409 0x04b0
ProductName: GlFmkNlcUz
FileVersion: 1.00
ProductVersion: 1.00
InternalName: rNJaAxktlR
OriginalFilename: rNJaAxktlR.exe

Worm.Win32.Vobfus.eryt also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Sresmon.Gen.1
CAT-QuickHealTrojan.Vobfus.gen
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeVBObfus.bn
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.6f1da1
BaiduWin32.Worm.Pronny.d
VirITWorm.Win32.VBNA.AWAG
SymantecW32.Changeup!gen35
tehtrisGeneric.Malware
ESET-NOD32Win32/Pronny.AC
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMAC
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.eryt
BitDefenderGen:Trojan.Sresmon.Gen.1
NANO-AntivirusTrojan.Win32.VB.ccdabr
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ABDC [Drp]
TencentTrojan.Win32.Koobface.p
EmsisoftGen:Trojan.Sresmon.Gen.1 (B)
F-SecureWorm.WORM/VB.jla
DrWebTrojan.VbCrypt.60
VIPREGen:Trojan.Sresmon.Gen.1
TrendMicroWORM_VOBFUS.SMAC
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.1eb06a16f1da1c35
SophosMal/VB-XV
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=86)
GoogleDetected
AviraWORM/VB.jla
VaristW32/Vobfus.V.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/VB.JL
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Sresmon.Gen.1
ZoneAlarmWorm.Win32.Vobfus.eryt
GDataGen:Trojan.Sresmon.Gen.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Diple.R13793
Acronissuspicious
VBA32Malware-Cryptor.VB.gen
TACHYONWorm/W32.Vobfus.159744.L
MalwarebytesGeneric.Malware.AI.DDS
PandaGeneric Malware
ZonerTrojan.Win32.88040
RisingWorm.Vobfus!1.99C7 (CLASSIC)
YandexTrojan.GenAsa!dkvjWaNX3jE
IkarusWorm.Win32.WBNA
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
BitDefenderThetaAI:Packer.2EAE27BF1F
AVGWin32:VB-ABDC [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudWorm:Win/Vobfus.671a95ca

How to remove Worm.Win32.Vobfus.eryt?

Worm.Win32.Vobfus.eryt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment