Trojan

Trojan.Win32.Jorik.Vobfus.fbkz (file analysis)

Malware Removal

The Trojan.Win32.Jorik.Vobfus.fbkz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Jorik.Vobfus.fbkz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Trojan.Win32.Jorik.Vobfus.fbkz?


File Info:

name: 2428B20E395C50B5BB8B.mlw
path: /opt/CAPEv2/storage/binaries/2a1c76e0f4eceef9e8fb59ba0c31ca5776cecd633819c8d39cfb85539b56bde4
crc32: 3C440A20
md5: 2428b20e395c50b5bb8baf3ac78cf0d4
sha1: 3c179f622e2a88b3b9be76a814cb53ee30fae136
sha256: 2a1c76e0f4eceef9e8fb59ba0c31ca5776cecd633819c8d39cfb85539b56bde4
sha512: 1aa581a390593a10a43fb1395144425e78d542f6a7f1630a7666f71c8023fe7c19a4190011248cb871aba0dd07d925decc7d8ae90d22f8bb9ea2d8264faaf1bb
ssdeep: 3072:ZfsvnEo1aZos9eH1aTy3bKanIgEzdyoJjQ:9Y9aZos9eH1H3bKGoz4q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E3C3193EFF8654A2E718357826E3C3C5197BA81AAF07A14BAB04375D5862F041C5CF67
sha3_384: e5c74b02bda6ff0ad867d0cc9cf57eb48ea280462bc77b21305d597caf5a421dd318262176c367b2c53342ddff232ad9
ep_bytes: 687c124000e8f0ffffff000000000000
timestamp: 2003-10-21 09:21:03

Version Info:

0: [No Data]

Trojan.Win32.Jorik.Vobfus.fbkz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.4!c
MicroWorld-eScanGen:Variant.Razy.796607
ClamAVWin.Trojan.Vobfus-49
FireEyeGeneric.mg.2428b20e395c50b5
CAT-QuickHealTrojan.Beebone.D
McAfeeVBObfus.dv
MalwarebytesMalware.AI.359507699
ZillyaTrojan.Jorik.Win32.1028537
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 003c363a1 )
AlibabaWorm:Win32/vobfus.1030
K7GWEmailWorm ( 003c363a1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Razy.DC27BF
BitDefenderThetaGen:NN.ZevbaF.36250.hmX@aWrNGob
VirITTrojan.Win32.Vobfus.FBKZ
CyrenW32/VB.HD.gen!Eldorado
SymantecW32.Changeup!gen20
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Pronny.BJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Jorik.Vobfus.fbkz
BitDefenderGen:Variant.Razy.796607
NANO-AntivirusTrojan.Win32.Jorik.covkpm
AvastWin32:Patched-AJW [Trj]
TencentTrojan.Win32.Jorik.hg
TACHYONTrojan/W32.VB-Jorik.126976.Q
EmsisoftGen:Variant.Razy.796607 (B)
BaiduWin32.Worm.VB.ad
F-SecureTrojan.TR/Barys.5614
DrWebWin32.HLLW.Autoruner1.23956
VIPREGen:Variant.Razy.796607
TrendMicroTROJ_GEN.R002C0CE423
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-Y
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Vbobf.b
AviraTR/Barys.5614
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftWorm:Win32/Vobfus.GF
ZoneAlarmTrojan.Win32.Jorik.Vobfus.fbkz
GDataWin32.Trojan.PSE.1M9X8JV
GoogleDetected
AhnLab-V3Worm/Win32.VBNA.C194278
Acronissuspicious
VBA32Trojan.Vobfus
ALYacGen:Variant.Razy.796607
MAXmalware (ai score=85)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0CE423
RisingTrojan.VBInject!1.64F2 (CLASSIC)
YandexTrojan.GenAsa!oScQzRI+lGo
IkarusWorm.Win32.VBNA
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:Patched-AJW [Trj]
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Jorik.Vobfus.fbkz?

Trojan.Win32.Jorik.Vobfus.fbkz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment