Worm

Worm.Win32.Vobfus.erzs removal guide

Malware Removal

The Worm.Win32.Vobfus.erzs is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.erzs virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.Vobfus.erzs?


File Info:

name: 3D935D1EC7A5B1D9BEAA.mlw
path: /opt/CAPEv2/storage/binaries/d9aa251984100493215d5324dda3699b4d22162c4c8a51d2ce68248aa41fe2b5
crc32: DC539303
md5: 3d935d1ec7a5b1d9beaab2934adee297
sha1: 1401b77924b8e29ea4c8daf4fb90bda31ea74c0f
sha256: d9aa251984100493215d5324dda3699b4d22162c4c8a51d2ce68248aa41fe2b5
sha512: f0a04408484d2a6fcd12881a0be0cc94fbea748a450bda5547b51ab4569d07bd8a79694cd8b5e3aba3877ce131fd8379d45c166b2f92544c6bd2f48c027fcaad
ssdeep: 3072:/L50Ak1iZKuPxqAXDdwCKYcQ+gqNAUjigdN:/LeAQATOX9NZBd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11804C6367780A67EC015D7F82C6F8350806DAC3811EAFA13F6D26A56B6F29779364343
sha3_384: 83730123cec36059b0b2c7c7ec61c894d06afd7f201b375afc3c8e8d232b922bb49863e63a7e52313e6d2bfd9d612a56
ep_bytes: 6894454000e8eeffffff000000000000
timestamp: 2012-07-03 12:11:42

Version Info:

Translation: 0x0409 0x04b0
Comments: Superlabial
CompanyName: Superlabial
FileDescription: Superlabial
LegalCopyright: Superlabial
LegalTrademarks: Superlabial
ProductName: Superlabial
FileVersion: 0.59
ProductVersion: 0.59
InternalName: distraught
OriginalFilename: distraught.exe

Worm.Win32.Vobfus.erzs also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.VBInject.11
ClamAVWin.Trojan.Changeup-6169544-0
CAT-QuickHealTrojan.Beebone.D
McAfeeVBObfus.df
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.ec7a5b
BitDefenderThetaGen:NN.ZevbaF.36318.km0@aifq1agi
VirITWorm.Win32.Generic.CDST
CyrenW32/Vobfus.BE.gen!Eldorado
SymantecW32.Changeup!gen18
ESET-NOD32a variant of Win32/AutoRun.VB.AXG
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.erzs
BitDefenderGen:Variant.VBInject.11
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ADOU [Trj]
TencentMalware.Win32.Gencirc.10b0ded3
EmsisoftGen:Variant.VBInject.11 (B)
BaiduWin32.Trojan.VBObfus.f
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.VbCrypt.60
VIPREGen:Variant.VBInject.11
TrendMicroWORM_VOBFUS.SM01
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.3d935d1ec7a5b1d9
SophosMal/VBCheMan-J
IkarusWorm.Win32.Vobfus
JiangminWorm/WBNA.dgmt
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftTrojan:Win32/Meredrop
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.VBInject.11
ViRobotWorm.Win32.A.WBNA.176128.AF
ZoneAlarmWorm.Win32.Vobfus.erzs
GDataGen:Variant.VBInject.11
GoogleDetected
AhnLab-V3Worm/Win32.WBNA.R29524
VBA32BScope.Trojan.Diple
ALYacGen:Variant.VBInject.11
MAXmalware (ai score=88)
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SM01
RisingWorm.AutoRun!1.E3CB (CLASSIC)
YandexTrojan.GenAsa!8fs7I17oTMA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.4231562.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-ADOU [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Worm.Win32.Vobfus.erzs?

Worm.Win32.Vobfus.erzs removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment