Trojan

Trojan.Win32.Jorik.Vobfus.fcdq removal guide

Malware Removal

The Trojan.Win32.Jorik.Vobfus.fcdq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Jorik.Vobfus.fcdq virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Jorik.Vobfus.fcdq?


File Info:

name: A957D96382BBA711A0A2.mlw
path: /opt/CAPEv2/storage/binaries/d25487a171f002c69ae0a641a146c2baf447ed437096596f28578b528a354849
crc32: 76820C4A
md5: a957d96382bba711a0a25568e61c8ed6
sha1: fe2a83b0a69fd13b1cc1df6d106117798284c437
sha256: d25487a171f002c69ae0a641a146c2baf447ed437096596f28578b528a354849
sha512: fb2b43f33ea4c472deaeb3b88b1cb25e47422984f4dca2d7d763e8ebe28cd1d4e7be8b158d90f1ad392785ce338ac705979feb376c46dab2303c53a2618e015e
ssdeep: 1536:xoDuxKPWt3oboa0G+UAqn2z3HldglfL3wi65IWS9qlmAhji6e:uDMKOtg9plAVelfTWI6lmAFi6e
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D8E3D83F3B8594C2E654257036FAC3D62ABF784A5F07414FA6047B1B28F2E642D2DA53
sha3_384: aa953d784f643744db689720be336a5b7d68b6cb920ff3316a6bd16fe245c5e0cfe55358bf421ad14c200911639c1bbe
ep_bytes: 6808134000e8eeffffff000058000000
timestamp: 2012-08-08 21:28:37

Version Info:

Translation: 0x0409 0x04b0
Comments: smemorate
CompanyName: smemorate
FileDescription: smemorate
LegalCopyright: smemorate
LegalTrademarks: smemorate
ProductName: smemorate
FileVersion: 8.53
ProductVersion: 8.53
InternalName: pterography
OriginalFilename: pterography.exe

Trojan.Win32.Jorik.Vobfus.fcdq also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.lwz0
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader6.42938
MicroWorld-eScanGen:Heur.VB.Agent.3
FireEyeGeneric.mg.a957d96382bba711
CAT-QuickHealTrojan.JorikMF.S28717795
ALYacGen:Heur.VB.Agent.3
MalwarebytesMalware.AI.2479362322
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 003c363a1 )
AlibabaWorm:Win32/vobfus.1030
K7GWP2PWorm ( 003cefdc1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.70117C5120
VirITTrojan.Win32.Cryptor.GL
CyrenW32/Vobfus.AQ.gen!Eldorado
SymantecW32.Changeup!gen20
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.AYD
APEXMalicious
ClamAVWin.Malware.Vobfus-6836774-0
KasperskyTrojan.Win32.Jorik.Vobfus.fcdq
BitDefenderGen:Heur.VB.Agent.3
NANO-AntivirusTrojan.Win32.Jorik.cnwrpf
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VBCrypt-BJA [Trj]
TencentWorm.Win32.Vobfus.q
EmsisoftGen:Heur.VB.Agent.3 (B)
F-SecureTrojan.TR/Dropper.VB.Gen5
BaiduWin32.Worm.VB.nu
VIPREGen:Heur.VB.Agent.3
TrendMicroWORM_VOBFUS.SM01
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.high.ml.score
SophosMal/Kovter-W
IkarusWorm.Win32.Vobfus
GDataGen:Heur.VB.Agent.3
JiangminTrojan/Jorik.hwao
GoogleDetected
AviraTR/Dropper.VB.Gen5
MAXmalware (ai score=80)
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.ABQ@4puwz1
ArcabitTrojan.VB.Agent.3
ViRobotTrojan.Win32.Vobfus.147456
ZoneAlarmTrojan.Win32.Jorik.Vobfus.fcdq
MicrosoftWorm:Win32/Vobfus.GP
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R42854
McAfeeGenDownloader.rv
TACHYONTrojan/W32.VB-Jorik.147456.F
VBA32Trojan.Vobfus
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM01
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!x8MiIhonRUk
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.4362996.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VBCrypt-BJA [Trj]
Cybereasonmalicious.382bba
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Jorik.Vobfus.fcdq?

Trojan.Win32.Jorik.Vobfus.fcdq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment