Trojan

Should I remove “Trojan.JorikMF.S27797009”?

Malware Removal

The Trojan.JorikMF.S27797009 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.JorikMF.S27797009 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.JorikMF.S27797009?


File Info:

name: 86B9A470AD07FB448DC2.mlw
path: /opt/CAPEv2/storage/binaries/f172ef0549f3a9cebbb43a99b6975d94cb957b37a0a1693d82dc6f5da108f07c
crc32: 87A306C6
md5: 86b9a470ad07fb448dc2f40c27894f95
sha1: 4c602b4d020d3025724ed6769155ed812917e175
sha256: f172ef0549f3a9cebbb43a99b6975d94cb957b37a0a1693d82dc6f5da108f07c
sha512: 17251817e92bb7cb99ebd2cf46ae78f32153b47e2bd3e96c98964922bc15c0444909a7f60ed0663206e2f50e48499f37e1d69b4672b4c9ad61ef449e642caa10
ssdeep: 3072:eGe2fdLbEame2YhFEryJVVtOTI4BkcKmPcfNV+/t:ddLAaNFHVVtO7KmkfNV+F
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11D14F83AFE8293A5D12A1A3639EBC7F506673C0D4F47800BAA5433E91DB1F341D69A47
sha3_384: ec390e0f50804b416d3b8a46249ceba1ca9c9054d381431c606b9d0be0cf5054e84db3c3e5e11bd9f1b63ad89963971c
ep_bytes: 6880134000e8eeffffff000000000000
timestamp: 2012-08-14 02:23:05

Version Info:

Translation: 0x0409 0x04b0
Comments: scomunica longeval
CompanyName: scomunica longeval
FileDescription: scomunica longeval
LegalCopyright: scomunica longeval
LegalTrademarks: scomunica longeval
ProductName: scomunica longeval
FileVersion: 8.20
ProductVersion: 8.20
InternalName: Halide
OriginalFilename: Halide.exe

Trojan.JorikMF.S27797009 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Heur.VB.Agent.3
ClamAVWin.Trojan.Vobfus-40
FireEyeGeneric.mg.86b9a470ad07fb44
CAT-QuickHealTrojan.JorikMF.S27797009
ALYacGen:Heur.VB.Agent.3
MalwarebytesGeneric.Worm.AutoRun.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.0ad07f
BaiduWin32.Worm.Pronny.eb
VirITWorm.Win32.X-Autorun.BKXN
CyrenW32/VB.HD.gen!Eldorado
SymantecW32.Changeup!gen20
Elasticmalicious (high confidence)
ESET-NOD32Win32/Pronny.CM
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Jorik.Vobfus.fcnj
BitDefenderGen:Heur.VB.Agent.3
NANO-AntivirusTrojan.Win32.Jorik.covkve
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-AEBR [Trj]
TencentWorm.Win32.Vobfus.m
TACHYONTrojan/W32.VB-Jorik.196608.J
EmsisoftGen:Heur.VB.Agent.3 (B)
F-SecureTrojan.TR/Barys.A.6305
DrWebWin32.HLLW.Autoruner1.24947
VIPREGen:Heur.VB.Agent.3
TrendMicroWORM_VOBFUS.SM01
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.high.ml.score
SophosMal/Kovter-W
GDataGen:Heur.VB.Agent.3
JiangminTrojan/Jorik.hwar
WebrootW32.Worm.Sm01
AviraTR/Barys.A.6305
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.ABQ@4puwz1
ArcabitTrojan.VB.Agent.3
ZoneAlarmTrojan.Win32.Jorik.Vobfus.fcnj
MicrosoftWorm:Win32/Vobfus.HF
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R33575
McAfeeGenDownloader.rv
MAXmalware (ai score=85)
VBA32Trojan.Vobfus
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM01
RisingWorm.VobfusEx!1.99DC (CLASSIC)
YandexTrojan.GenAsa!3dwChsaCCXs
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.AU!tr
BitDefenderThetaGen:NN.ZevbaF.36250.mm0@ae8seQgi
AVGWin32:VB-AEBR [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.JorikMF.S27797009?

Trojan.JorikMF.S27797009 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment