Trojan

How to remove “Trojan.Win32.Jorik.Vobfus.fcef”?

Malware Removal

The Trojan.Win32.Jorik.Vobfus.fcef is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Jorik.Vobfus.fcef virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Trojan.Win32.Jorik.Vobfus.fcef?


File Info:

name: 63072D3C2585C38326D1.mlw
path: /opt/CAPEv2/storage/binaries/f5a41adec7cea2239e9365b0a4c2864df95eb9a3d4df881fe3a7c9938538abfd
crc32: 145C32B8
md5: 63072d3c2585c38326d1733c1f5ed4e5
sha1: c922d7a897332a68f66fa328a33d924f27cabcde
sha256: f5a41adec7cea2239e9365b0a4c2864df95eb9a3d4df881fe3a7c9938538abfd
sha512: 1c3d1a9bcd828fbb642e76eefe2bfb6345dee51de6cb6abdf552981eaf90560a45319ff28a2d0ee806044fb1b20fdd66a5fb56dd670aaaef27df160b03c943c2
ssdeep: 1536:2/EnMlq9hkJIQNhAdPt9w3f85KmCivE48yIN3HUOwirIUuEpmAhjiGs:TMlkkJIQNhswy2pmAFiGs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T124F3427EBE2DD460E715283436F2C3A61963695DBD0B818BA7003BDFD8A6F244C1CA57
sha3_384: 9a12608dff35861f20cbcd0aa25603cccd2b0e299c353a0b31f918d3826dd24f2d458933b5853f8117c1ac5ddd0fb405
ep_bytes: 68c0124000e8f0ffffff000000000000
timestamp: 2012-08-09 06:21:23

Version Info:

Translation: 0x0409 0x04b0
Comments: Originative truish
CompanyName: Originative truish
FileDescription: Originative truish
LegalCopyright: Originative truish
LegalTrademarks: Originative truish
ProductName: Originative truish
FileVersion: 3.93
ProductVersion: 3.93
InternalName: Vietereste
OriginalFilename: Vietereste.exe

Trojan.Win32.Jorik.Vobfus.fcef also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.4!c
MicroWorld-eScanGen:Heur.VB.Agent.3
ClamAVWin.Malware.Vobfus-6750588-0
FireEyeGeneric.mg.63072d3c2585c383
CAT-QuickHealTrojan.JorikMF.S21116013
ALYacGen:Heur.VB.Agent.3
MalwarebytesMalware.AI.3592228592
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/vobfus.1030
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.c2585c
BitDefenderThetaGen:NN.ZevbaF.36250.jm0@aygcZkli
VirITWorm.Win32.X-Autorun.BKRC
CyrenW32/Vobfus.AQ.gen!Eldorado
SymantecW32.Changeup!gen20
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.AYE
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Jorik.Vobfus.fcef
BitDefenderGen:Heur.VB.Agent.3
NANO-AntivirusTrojan.Win32.Jorik.covllh
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VBCrypt-BJA [Trj]
TencentWorm.Win32.Vobfus.q
EmsisoftGen:Heur.VB.Agent.3 (B)
BaiduWin32.Worm.VB.mq
F-SecureTrojan.TR/Jorik.Vobfus.JH.1
DrWebWin32.HLLW.Autoruner1.24780
VIPREGen:Heur.VB.Agent.3
TrendMicroWORM_VOBFUS.SMJO
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.high.ml.score
SophosMal/Kovter-W
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.7HQW10
JiangminTrojan/Vbobf.b
AviraTR/Jorik.Vobfus.JH.1
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.ABQ@4puwz1
ArcabitTrojan.VB.Agent.3
ZoneAlarmTrojan.Win32.Jorik.Vobfus.fcef
MicrosoftWorm:Win32/Vobfus.GP
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R42854
McAfeeGenDownloader.rv
MAXmalware (ai score=84)
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMJO
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!CWah9dg96Y4
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.AU!tr
AVGWin32:VBCrypt-BJA [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Jorik.Vobfus.fcef?

Trojan.Win32.Jorik.Vobfus.fcef removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment