Trojan

Trojan.Win32.Jorik.Vobfus.fawi (file analysis)

Malware Removal

The Trojan.Win32.Jorik.Vobfus.fawi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Jorik.Vobfus.fawi virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Jorik.Vobfus.fawi?


File Info:

name: 0EF4E091BEE2F1C9ACDF.mlw
path: /opt/CAPEv2/storage/binaries/6c879aca95da7bd5e2256619fc02b2d594e83abc46c5101d3ed8eb48a7a49b34
crc32: 923257B5
md5: 0ef4e091bee2f1c9acdffa479446f501
sha1: ffc9c345f013680df2aab15f896ba8f0f5aa930d
sha256: 6c879aca95da7bd5e2256619fc02b2d594e83abc46c5101d3ed8eb48a7a49b34
sha512: e30763899e4b3bed0e5168231dab40551dfa70f31a5f53c176266d4142657bfec43ee95842f1640308506ac557bd57ec8958c358e24fce7c4ad3046faf6c5876
ssdeep: 3072:B6v7777777777777777H77777777777777777777777777777tUaIqcNBca1L:mUaILNBc0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EBD3715A3F629821F614583F59F243F615BBAB4E7B0BD08FDE406DDB19A6F200C24927
sha3_384: 1c7610eb1e8588f138d91a63ce3d07f6fd7f162a4754a698d2bfb25688ba88e6076cc8a97cacd1b1f813735f3919e86f
ep_bytes: 68b8124000e8f0ffffff000000000000
timestamp: 1996-11-12 21:31:43

Version Info:

0: [No Data]

Trojan.Win32.Jorik.Vobfus.fawi also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.ts9c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.0ef4e091bee2f1c9
CAT-QuickHealTrojan.JorikMF.S19994017
McAfeeW32/Autorun.worm.aaeh
Cylanceunsafe
ZillyaTrojan.Jorik.Win32.1031239
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 003c363a1 )
AlibabaWorm:Win32/vobfus.1030
K7GWEmailWorm ( 003c363a1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITWorm.Win32.X-Autorun.BJQB
CyrenW32/VB.HD.gen!Eldorado
SymantecW32.Changeup
ESET-NOD32a variant of Win32/VBObfus.RM
APEXMalicious
ClamAVWin.Trojan.VBTrojan3-6118226-0
KasperskyTrojan.Win32.Jorik.Vobfus.fawi
BitDefenderGen:Trojan.Heur.VP2.imX@auXsGrn
NANO-AntivirusTrojan.Win32.Jorik.crgjjr
MicroWorld-eScanGen:Trojan.Heur.VP2.imX@auXsGrn
AvastWin32:VB-ADXE [Trj]
TencentTrojan.Win32.Vobfus.ya
TACHYONTrojan/W32.VB-Jorik.131072.U
EmsisoftGen:Trojan.Heur.VP2.imX@auXsGrn (B)
F-SecureWorm.WORM/Vobfus.GFJ
DrWebWin32.HLLW.Autoruner1.24077
VIPREGen:Trojan.Heur.VP2.imX@auXsGrn
TrendMicroTSPY_VOBFUS_BK0840E9.TOMC
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.high.ml.score
SophosMal/VBCheMan-J
IkarusWorm.Win32.VBNA
GDataGen:Trojan.Heur.VP2.imX@auXsGrn
JiangminTrojan.Jorik.atzb
AviraWORM/Vobfus.GFJ
Antiy-AVLWorm/Win32.WBNA.gen
ArcabitTrojan.Heur.VP2.EE374A
ViRobotWorm.Win32.A.VBNA.122880.CH
ZoneAlarmTrojan.Win32.Jorik.Vobfus.fawi
MicrosoftWorm:Win32/Vobfus.GF
GoogleDetected
AhnLab-V3Worm/Win.VBNA.R509559
Acronissuspicious
BitDefenderThetaAI:Packer.5BFFC8751F
ALYacGen:Trojan.Heur.VP2.imX@auXsGrn
MAXmalware (ai score=83)
VBA32SScope.Malware-Cryptor.VBCR.3042
MalwarebytesVBObfus.Worm.Spreader.DDS
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallTSPY_VOBFUS_BK0840E9.TOMC
RisingTrojan.VB!1.99F7 (CLASSIC)
YandexTrojan.GenAsa!f1AXRGSDLPY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.4320202.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VB-ADXE [Trj]
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Jorik.Vobfus.fawi?

Trojan.Win32.Jorik.Vobfus.fawi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment