Trojan

Trojan.Win32.Jorik.Vobfus.eyod removal guide

Malware Removal

The Trojan.Win32.Jorik.Vobfus.eyod is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Jorik.Vobfus.eyod virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Jorik.Vobfus.eyod?


File Info:

name: ECF2709EDBB0980809B1.mlw
path: /opt/CAPEv2/storage/binaries/a4d37557fce7808d38b541fb8d14e47b57df0c1f0f6ef2e30039aad88eb5deed
crc32: 06BBF91F
md5: ecf2709edbb0980809b1a0ab679709a5
sha1: 9922b2cf01edb68ce48d58d2c80d8d4573f16d19
sha256: a4d37557fce7808d38b541fb8d14e47b57df0c1f0f6ef2e30039aad88eb5deed
sha512: 54e9eeea92650ffd75411767fd56ff1b9872e9bb0a838f86fb8c05488e430224c89eaddebf9202349b8b9ba5e2760825b7708d920f2a9f469768d3ae3fbbf54e
ssdeep: 1536:qlHy9ddd7Y1idNzL7zdddXOpdxCTkUjW/dQqdUxpkddAd3nddd4od5ddMk5dSt2o:oxez7rr6EFJ0T72mBT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16B1451D271C4D46DC57CDF3C239E86F23CD16A0BA50B4E6FA364EF695C26A182724632
sha3_384: d1040c63918532bb70a15f6c20b7768cb0a4185a5186e1c13b2000f5a83de4b7e0b0e2e24cecbec49aefd7aacc4b5677
ep_bytes: 6820124000e8f0ffffff000000000000
timestamp: 2012-06-27 22:44:29

Version Info:

0: [No Data]

Trojan.Win32.Jorik.Vobfus.eyod also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.ld53
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.99211
ClamAVWin.Worm.Vobfus-6875093-0
FireEyeGeneric.mg.ecf2709edbb09808
CAT-QuickHealTrojan.Beebone.D
McAfeeVBObfus.n
MalwarebytesPronny.Worm.Spreader.DDS
VIPRETrojan.GenericKDZ.99211
SangforSuspicious.Win32.Save.vb
K7AntiVirusNetWorm ( 700000151 )
AlibabaWorm:Win32/Jorik.8caa3762
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.edbb09
BitDefenderThetaGen:NN.ZevbaF.36250.mmZ@aCJ95qc
VirITWorm.Win32.X-Autorun.BAUV
CyrenW32/VBKrypt.BJD.gen!Eldorado
SymantecW32.Changeup
ESET-NOD32Win32/Pronny.BE
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Jorik.Vobfus.eyod
BitDefenderTrojan.GenericKDZ.99211
NANO-AntivirusTrojan.Win32.Jorik.cfdsms
AvastWin32:Jorik-JI [Trj]
TencentTrojan.Win32.Vobfus.hcq
SophosMal/SillyFDC-Y
BaiduWin32.Worm.Autorun.w
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebWin32.HLLW.Autoruner1.18117
ZillyaTrojan.Jorik.Win32.1039792
TrendMicroTROJ_GEN.R002C0CEJ23
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cz
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.99211 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Vbobf.b
WebrootW32.Vobfus.Gen
AviraTR/Patched.Ren.Gen
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftWorm:Win32/Vobfus.gen!W
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Generic.D1838B
ZoneAlarmTrojan.Win32.Jorik.Vobfus.eyod
GDataWin32.Trojan.PSE.1IGMVDB
GoogleDetected
VBA32Trojan.Vobfus
ALYacTrojan.GenericKDZ.99211
MAXmalware (ai score=86)
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallTROJ_GEN.R002C0CEJ23
RisingTrojan.VB!1.99F7 (CLASSIC)
YandexTrojan.GenAsa!0Ax3ct62bfs
IkarusWorm.Win32.AutoRun
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.C!tr
AVGWin32:Jorik-JI [Trj]
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Jorik.Vobfus.eyod?

Trojan.Win32.Jorik.Vobfus.eyod removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment