Trojan

Trojan.Win32.Jorik.Vobfus.dnpz information

Malware Removal

The Trojan.Win32.Jorik.Vobfus.dnpz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Jorik.Vobfus.dnpz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Jorik.Vobfus.dnpz?


File Info:

name: 2588C1B2606FC240A1E9.mlw
path: /opt/CAPEv2/storage/binaries/b3e1b20f4c6a0a6f92eef41a3ac89ff5c8669fc23169df0252a783002bc8053e
crc32: CBC2E2B0
md5: 2588c1b2606fc240a1e97bf8b63e17c7
sha1: 5d38764d551e467d8ff48c1a9a09040815303d06
sha256: b3e1b20f4c6a0a6f92eef41a3ac89ff5c8669fc23169df0252a783002bc8053e
sha512: 3044fffd0dd24076fe628e3999bd889053c0ed90e00bf0999db0a6e64ed627dedd9c3a9189247a17de6bc6c87b9b26a116704d7a15d614dc2149b98a05197c86
ssdeep: 6144:O/GPHPr5dFvW8HGzNz8I4vDWsQFN2cSnuXLH6M:8GPHVdFvW8Hu/4vDKFdXL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A56494BEBF44C8A5D09C01743BE6F3E611E330494E67C742576163A468AFDA25C9CB8B
sha3_384: 28d44b7b9cdaf6086f2a9eede5a7bce9e44a5046b81b2496a37454c4129cadfda74cc813bf2e70ce7c74053080ab2f56
ep_bytes: 6814134000e8f0ffffff000000000000
timestamp: 2005-11-29 18:25:11

Version Info:

0: [No Data]

Trojan.Win32.Jorik.Vobfus.dnpz also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lx0v
DrWebWin32.HLLW.Autoruner1.35581
MicroWorld-eScanGen:Variant.Zusy.458539
ClamAVWin.Trojan.Vobfus-23
CAT-QuickHealTrojan.Beebone.D
ALYacGen:Variant.Zusy.458539
Cylanceunsafe
ZillyaTrojan.Jorik.Win32.77605
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaMalware:Win32/km_2faa.None
K7GWEmailWorm ( 003c363a1 )
K7AntiVirusEmailWorm ( 003c363a1 )
BitDefenderThetaGen:NN.ZevbaF.36250.tqZ@aaFthVp
CyrenW32/Vobfus.SB.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/Pronny.AS
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Jorik.Vobfus.dnpz
BitDefenderGen:Variant.Zusy.458539
NANO-AntivirusTrojan.Win32.Jorik.cqkxue
AvastWin32:Vitro [Inf]
TencentTrojan.Win32.Jorik.hd
TACHYONTrojan/W32.VB-Jorik.315392.O
EmsisoftGen:Variant.Zusy.458539 (B)
F-SecureTrojan.TR/Barys.2490.jh
VIPREGen:Variant.Zusy.458539
TrendMicroTROJ_GEN.R002C0CF323
McAfee-GW-EditionBehavesLike.Win32.Generic.ft
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.2588c1b2606fc240
SophosMal/Generic-S
IkarusWorm.Win32.Vobfus
GDataWin32.Trojan.PSE.10T9JN3
AviraTR/Barys.2490.jh
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.VB.DNPZ@4p78ez
ArcabitTrojan.Zusy.D6FF2B
ZoneAlarmTrojan.Win32.Jorik.Vobfus.dnpz
MicrosoftWorm:Win32/Vobfus.FD
GoogleDetected
AhnLab-V3Trojan/Win32.Vobfus.R188257
Acronissuspicious
McAfeeVBObfus.dv
MAXmalware (ai score=80)
VBA32Trojan.Vobfus
MalwarebytesMalware.AI.2751437790
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0CF323
RisingWorm.Pronny!1.AE42 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/VBObfus.AU!tr
AVGWin32:Vitro [Inf]
Cybereasonmalicious.2606fc
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Jorik.Vobfus.dnpz?

Trojan.Win32.Jorik.Vobfus.dnpz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment