Trojan

Trojan.JorikVMF.S19741166 (file analysis)

Malware Removal

The Trojan.JorikVMF.S19741166 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.JorikVMF.S19741166 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Trojan.JorikVMF.S19741166?


File Info:

name: 2FC3981C6F2E9888F5BD.mlw
path: /opt/CAPEv2/storage/binaries/8910a4a1c3ab27611751551715edcc4fab4ff113a09b2c8442660979706a4106
crc32: D72E2B97
md5: 2fc3981c6f2e9888f5bde2adbcd54df1
sha1: 03b99d3597b21560e2acf47b8f1f8dac9f94cf6a
sha256: 8910a4a1c3ab27611751551715edcc4fab4ff113a09b2c8442660979706a4106
sha512: a0fe65992b774a6274c4a30ce9b46cd63c32cd04dc53dc049e14d30b9273bdcb5c037f91ce207fababf66a497dc591d775109245eb56e10c5aab0f0e2354c709
ssdeep: 3072:eWQMlXL7KvWeRl6Knvmb7/D26DKcAA6vQOm34lK5/si+iS36:7XCVREKnvmb7/D26DKcV67m34E5/s8SK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F004D812BA09B06BE183D4F05E28C69A392D6D7623D0BC4777857F296A70597B8F031F
sha3_384: aa81c9af56f9d4992289ccca2ba30c4841f280ac7aa6e8a1baa541b1c933c6903a2234ec16dd27ca4ee1519fdf20c896
ep_bytes: 6828384000e8eeffffff000000000000
timestamp: 2011-12-05 18:17:21

Version Info:

0: [No Data]

Trojan.JorikVMF.S19741166 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Sirefef.942
CAT-QuickHealTrojan.JorikVMF.S19741166
SkyhighBehavesLike.Win32.VBObfus.cm
McAfeeVBObfus.cd
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.c6f2e9
BaiduWin32.Worm.Autorun.l
VirITTrojan.Win32.Vobfus.KDN
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/AutoRun.VB.AQE
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.efhi
BitDefenderGen:Variant.Sirefef.942
NANO-AntivirusTrojan.Win32.Jorik.cqkyjh
SUPERAntiSpywareTrojan.Agent/Gen-Remnat[VB]
AvastWin32:VB-AAET [Trj]
TencentWorm.Win32.Vobfus.kq
EmsisoftGen:Variant.Sirefef.942 (B)
F-SecureTrojan.TR/Dropper.Gen7
DrWebTrojan.VbCrypt.81
VIPREGen:Variant.Sirefef.942
TrendMicroWORM_VOBFUS.SMAB
FireEyeGeneric.mg.2fc3981c6f2e9888
SophosMal/SillyFDC-T
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=80)
GoogleDetected
AviraTR/Dropper.Gen7
VaristW32/Vobfus.AA.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Sirefef.942
ViRobotTrojan.Win32.Jorik.188416.B
ZoneAlarmWorm.Win32.Vobfus.efhi
GDataGen:Variant.Sirefef.942
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R16967
Acronissuspicious
BitDefenderThetaAI:Packer.AE453EB620
ALYacGen:Variant.Sirefef.942
TACHYONTrojan/W32.VB-Jorik.188416.I
VBA32BScope.Trojan.Jorik
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMAB
RisingWorm.AutoRun!1.E3C6 (CLASSIC)
YandexTrojan.GenAsa!x1tuGxxa0wU
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-AAET [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudWorm:Win/Vobfus.98fd7202

How to remove Trojan.JorikVMF.S19741166?

Trojan.JorikVMF.S19741166 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment