Trojan

Trojan.JorikMF.S21116013 removal

Malware Removal

The Trojan.JorikMF.S21116013 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.JorikMF.S21116013 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Trojan.JorikMF.S21116013?


File Info:

name: 65FCE531412A6C239378.mlw
path: /opt/CAPEv2/storage/binaries/f55591fe1345c9a0c0f64f72e7639d2a3c351694fb1dd11fe50a0513deda89e1
crc32: C693709A
md5: 65fce531412a6c23937829aefeffecd6
sha1: 76f6d099c4427caa4ea4225c93af65e19af8d77c
sha256: f55591fe1345c9a0c0f64f72e7639d2a3c351694fb1dd11fe50a0513deda89e1
sha512: a9374e05ca9d0bef808b4721128d970b6cd79901f544f9fe432c496f603526ef0c2baf4dd38010a946a49bb39820c574f71cff0a1a21aec8032fbf3203726188
ssdeep: 1536:2wEnMlq9hkJRNhAdPt9w3f85KmCivE48yIN3HUOwirIUuEpmAhjiGs:MMlkkJRNhswy2pmAFiGs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A2F3427EBE2DD460E715283436F2C3A60963695DBD0B818BA7003BDFD8A6F244C1CA57
sha3_384: 549e1f9b4748591b0429b7290092916c6cc17d0de22a17933d34c0980be4dab8509901b08bb573fa5b4bb592c3b95cfe
ep_bytes: 68c0124000e8f0ffffff000000000000
timestamp: 2012-08-09 06:21:23

Version Info:

Translation: 0x0409 0x04b0
Comments: Originative truish
CompanyName: Originative truish
FileDescription: Originative truish
LegalCopyright: Originative truish
LegalTrademarks: Originative truish
ProductName: Originative truish
FileVersion: 3.93
ProductVersion: 3.93
InternalName: Vietereste
OriginalFilename: Vietereste.exe

Trojan.JorikMF.S21116013 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.4!c
MicroWorld-eScanGen:Heur.VB.Agent.3
ClamAVWin.Malware.Vobfus-6750588-0
FireEyeGeneric.mg.65fce531412a6c23
CAT-QuickHealTrojan.JorikMF.S21116013
McAfeeGenDownloader.rv
MalwarebytesMalware.AI.3592228592
ZillyaTrojan.Jorik.Win32.1014383
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/vobfus.1030
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.1412a6
ArcabitTrojan.VB.Agent.3
BitDefenderThetaGen:NN.ZevbaF.36250.jm0@aygcZkli
VirITWorm.Win32.X-Autorun.BKRC
CyrenW32/Vobfus.AQ.gen!Eldorado
SymantecW32.Changeup!gen20
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.AYE
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Jorik.Vobfus.fcef
BitDefenderGen:Heur.VB.Agent.3
NANO-AntivirusTrojan.Win32.Jorik.covllh
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VBCrypt-BJA [Trj]
RisingWorm.VobfusEx!1.99DB (CLASSIC)
EmsisoftGen:Heur.VB.Agent.3 (B)
BaiduWin32.Worm.VB.mq
F-SecureTrojan.TR/Jorik.Vobfus.JH.1
DrWebWin32.HLLW.Autoruner1.24780
VIPREGen:Heur.VB.Agent.3
TrendMicroWORM_VOBFUS.SMJO
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.high.ml.score
SophosMal/Kovter-W
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Vbobf.b
AviraTR/Jorik.Vobfus.JH.1
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.ABQ@4puwz1
MicrosoftWorm:Win32/Vobfus.GP
ZoneAlarmTrojan.Win32.Jorik.Vobfus.fcef
GDataWin32.Trojan.PSE.7HQW10
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R42854
VBA32TScope.Trojan.VB
ALYacGen:Heur.VB.Agent.3
MAXmalware (ai score=87)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMJO
TencentWorm.Win32.Vobfus.q
YandexTrojan.GenAsa!CWah9dg96Y4
IkarusWorm.Win32.Vobfus
FortinetW32/VBObfus.AU!tr
AVGWin32:VBCrypt-BJA [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.JorikMF.S21116013?

Trojan.JorikMF.S21116013 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment