Worm

What is “Worm:Win32/Vobfus.LZ”?

Malware Removal

The Worm:Win32/Vobfus.LZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Vobfus.LZ virus can do?

  • Executable code extraction
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Worm:Win32/Vobfus.LZ?


File Info:

crc32: C97D901B
md5: ba9e42dd048a71c21b4b32d0a08cc358
name: BA9E42DD048A71C21B4B32D0A08CC358.mlw
sha1: f6013b65cb7af5c33297a99acc246091834ad4f7
sha256: bfe90a3c3c0a837e06ab6242f14ab706adb28e22cc79877bad616e1d38cfd72b
sha512: 6e45aae43307943f1e6bf6f4616c94703eef041e17f14cb9b1a734281fa8805aa21ce8abd4e3e02328d107bc7e3f0ba3d45c28d9fbc9891f514728a1639b81d6
ssdeep: 6144:3aRvu2WMyjz81jAi349syfYvXcVUEu2IqHaNb8lj4:K5u2WdMn3WfQvCHSYl8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: charbon
FileVersion: 8.53
CompanyName: 009
ProductName: Clittor
ProductVersion: 8.53
OriginalFilename: charbon.exe

Worm:Win32/Vobfus.LZ also known as:

BkavHW32.Packed.
K7AntiVirusTrojan ( 005640b91 )
DrWebWin32.HLLW.Autoruner1.30125
MicroWorld-eScanGen:Variant.Razy.456582
CMCWorm.Win32.Vobfus!O
CAT-QuickHealTrojan.Beebone.D
ALYacGen:Variant.Razy.456582
CylanceUnsafe
ZillyaWorm.WBNAGen.Win32.26
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/Vobfus.d875bdcc
K7GWTrojan ( 005640b91 )
Cybereasonmalicious.d048a7
TrendMicroWORM_VOBFUS.SMIS
CyrenW32/Vobfus.BI.gen!Eldorado
SymantecW32.Changeup!gen22
ESET-NOD32Win32/VBObfus.SK
ZonerTrojan.Win32.82427
APEXMalicious
TotalDefenseWin32/VBDoc.A!generic
AvastWin32:VB-AFDO [Trj]
ClamAVWin.Worm.Vobfus-6823593-0
GDataGen:Variant.Razy.456582
KasperskyWorm.Win32.WBNA.ipa
BitDefenderGen:Variant.Razy.456582
NANO-AntivirusTrojan.Win32.Vobfus.fsfxee
ViRobotWorm.Win32.A.VBNA.200704.AQ
SUPERAntiSpywareTrojan.Agent/Gen-Vban
TencentMalware.Win32.Gencirc.10b58696
Ad-AwareGen:Variant.Razy.456582
SophosW32/VBNA-U
ComodoTrojWare.Win32.VB.ISCI@4snddz
F-SecureWorm.WORM/Conficker.AT
BitDefenderThetaGen:NN.ZevbaF.34110.ym3@aG@Mwgci
VIPREWorm.Win32.VBNA.bb (v)
Invinceaheuristic
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.ba9e42dd048a71c2
EmsisoftGen:Variant.Razy.456582 (B)
SentinelOneDFI – Malicious PE
F-ProtW32/Vobfus.BI.gen!Eldorado
Endgamemalicious (high confidence)
WebrootW32.Trojan.Gen
AviraWORM/Conficker.AT
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftWorm:Win32/Vobfus.LZ
JiangminWorm/VBNA.gxdy
ArcabitTrojan.Razy.D6F786
AegisLabWorm.Win32.WBNA.lEIg
ZoneAlarmWorm.Win32.WBNA.ipa
AhnLab-V3Worm/Win32.VBNA.R123347
Acronissuspicious
McAfeeVBObfus.ey
MAXmalware (ai score=80)
VBA32TScope.Trojan.VB
MalwarebytesWorm.Vobfus
PandaW32/Vobfus.gen.worm
TrendMicro-HouseCallWORM_VOBFUS.SMIS
RisingTrojan.Vobfus!1.BAE4 (CLOUD)
IkarusTrojan.Win32.VBObfus
MaxSecureWin.MxResIcn.Heur.Gen
FortinetW32/WBNA.IPA!worm
AVGWin32:VB-AFDO [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Worm.3d4

How to remove Worm:Win32/Vobfus.LZ?

Worm:Win32/Vobfus.LZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment