Malware

What is “Win32/VBObfus.FZ”?

Malware Removal

The Win32/VBObfus.FZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware - Review 2020

GridinSoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend to use GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the TRIAL period.
6-day free trial available.

What Win32/VBObfus.FZ virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/VBObfus.FZ?


File Info:

name: 830291703A7ED241E6D1.mlw
path: /opt/CAPEv2/storage/binaries/56ee593063dea67358f714c88bd5b5c9f65df61412a5ae9c78a3852615898363
crc32: 7BF6ACE8
md5: 830291703a7ed241e6d16651854a93d3
sha1: 0970987dad02643f701bfd65e10ed7f8885aae77
sha256: 56ee593063dea67358f714c88bd5b5c9f65df61412a5ae9c78a3852615898363
sha512: 1f21883f10773e3906d0b8974d7279f224417655f68f8fd6e5113eb1778401f7358a3cfa6fb645005d4fdac13374e31423f7c91110fc0355ab7bdeca0283bd0a
ssdeep: 6144:e4anI56piIqQUuDnr3G5q/MEuolGjS7ZGll197SDfib12GaNK1mk9xqSj+iQVlDu:elI56piIqQUuDnr3G0/iolGjS7ZGll1j
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F88442143740F639E01685F53F0487B88539A93505E0AC07FB81BBA266B5EBFD6B6723
sha3_384: 7321e3a78e43e4f30be396929b79e75df3a9ef3220f30f7310c0566e629c5083d3f2b7b2512c12afa1403cff136d6baa
ep_bytes: 00000000000000000000000000000000
timestamp: 1999-07-12 04:13:02

Version Info:

Translation: 0x0409 0x04b0
Comments: speravi verdetto
CompanyName: speravi verdetto
FileDescription: speravi verdetto
LegalCopyright: speravi verdetto
LegalTrademarks: speravi verdetto
ProductName: speravi verdetto
FileVersion: 5.87
ProductVersion: 5.87
InternalName: sparrowbill
OriginalFilename: sparrowbill.exe

Win32/VBObfus.FZ also known as:

BkavW32.AIDetect.malware1
LionicWorm.Win32.WBNA.low6
tehtrisGeneric.Malware
Sangfor[MICROSOFT VISUAL BASIC V6.0]
K7AntiVirusTrojan ( 0040f56b1 )
K7GWTrojan ( 0040f56b1 )
Cybereasonmalicious.dad026
VirITTrojan.Win32.Generic.AJQX
CyrenW32/Vobfus.BE.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/VBObfus.FZ
ClamAVWin.Trojan.Changeup-6169544-0
NANO-AntivirusVirus.Win32.Gen.ccmw
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ADSU [Trj]
TencentTrojan.Win32.FakeFolder.abh
ComodoWorm.Win32.Pronny.BL@4pn6lp
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Worm.Pronny.d
McAfee-GW-EditionBehavesLike.Win32.Backdoor.fm
SentinelOneStatic AI – Malicious PE
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.830291703a7ed241
SophosML/PE-A
IkarusWorm.Win32.Vobfus
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.VBNA.R30730
McAfeeGenDownloader.pr
MalwarebytesWorm.Obfuscator
APEXMalicious
RisingWorm.VobfusEx!1.99E2 (CLASSIC)
YandexTrojan.GenAsa!DSiKajy8TVg
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.F
AVGWin32:VB-ADSU [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/VBObfus.FZ?

Win32/VBObfus.FZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment