Worm

What is “Worm.Win32.Vobfus.ole”?

Malware Removal

The Worm.Win32.Vobfus.ole is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.ole virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm.Win32.Vobfus.ole?


File Info:

name: 7E05200039119BBBFDF9.mlw
path: /opt/CAPEv2/storage/binaries/3753c56e8390475a8d2af609854e1c40d80f787aa7fa3fa3b98c224e9132d3cf
crc32: 6CB7519C
md5: 7e05200039119bbbfdf902086a319989
sha1: 8aefa5e67d7feb128d3dfebdc943f81e7fe96353
sha256: 3753c56e8390475a8d2af609854e1c40d80f787aa7fa3fa3b98c224e9132d3cf
sha512: 05678b5f05cbf4470a6771aff372837b2d201ca42e21fbfe90573fc6afb368c293cd9f97b7710000af977aca0d64757124cfe6d69d76f036ab24c18ccdedc92b
ssdeep: 1536:Ipl/QYyj5uhDkwI/qpZbo1cIDDxIH6bLBn23pT6D9WjwXeb7E0zQLQIOXAEzD/I+:GOYyjGDDICHbomqIQ7Dq7E0zQLQTAEW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DE14B43BBF484899D96C62782BF6C7E61273F8599A078267521437A92C93F500D3CB4F
sha3_384: 5b16070cc5ef5f98d55516df8231ad1042241e7e6d1eb1f18c8774a23676861dd9e9c8d0346098c9bc596ea2422a810d
ep_bytes: 68d8124000e8eeffffff000000000000
timestamp: 2001-05-11 19:29:31

Version Info:

0: [No Data]

Worm.Win32.Vobfus.ole also known as:

MicroWorld-eScanGen:Variant.Barys.431194
ClamAVWin.Trojan.VB-1604
CAT-QuickHealTrojan.Beebone.D
McAfeeW32/Autorun.worm.aaeh
MalwarebytesMalware.AI.4018306249
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (D)
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
BaiduWin32.Worm.Pronny.ek
VirITTrojan.Win32.Generic.ARJ
CyrenW32/VB.HE.gen!Eldorado
SymantecW32.Changeup!gen20
Elasticmalicious (high confidence)
ESET-NOD32Win32/Pronny.DQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.ole
BitDefenderGen:Variant.Barys.431194
NANO-AntivirusTrojan.Win32.VB.cmxslb
AvastWin32:Vitro [Inf]
TencentWorm.Win32.Vobfus.kn
TACHYONTrojan/W32.VB-Agent.196608.FD
EmsisoftGen:Variant.Barys.431194 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner1.25602
VIPREGen:Variant.Barys.431194
McAfee-GW-EditionBehavesLike.Win32.Generic.cz
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.7e05200039119bbb
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Barys.431194
JiangminTrojan/Vbobf.b
WebrootTrojan.Win32.Diple
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
ArcabitTrojan.Barys.D6945A
ZoneAlarmWorm.Win32.Vobfus.ole
MicrosoftWorm:Win32/Vobfus.HR
GoogleDetected
BitDefenderThetaGen:NN.ZevbaF.36250.mqZ@aa9pq2e
ALYacGen:Variant.Barys.431194
MAXmalware (ai score=84)
VBA32Worm.VBNA
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.VB!1.99F7 (CLASSIC)
YandexTrojan.GenAsa!UE+Poba9A1w
IkarusTrojan-Downloader.Win32.Beebone
FortinetW32/VBObfus.AU!tr
AVGWin32:Vitro [Inf]
Cybereasonmalicious.039119
DeepInstinctMALICIOUS

How to remove Worm.Win32.Vobfus.ole?

Worm.Win32.Vobfus.ole removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment