Trojan

Trojan.Win32.Jorik.Vobfus.gdcp (file analysis)

Malware Removal

The Trojan.Win32.Jorik.Vobfus.gdcp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Jorik.Vobfus.gdcp virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Jorik.Vobfus.gdcp?


File Info:

name: E22E4D4B9199CB2E7415.mlw
path: /opt/CAPEv2/storage/binaries/db7e2c547dfa7eb11e7bf9e637450bc9e8bee45898998cc879d1f31eb950ae68
crc32: 837041BA
md5: e22e4d4b9199cb2e7415f51c3f8802cf
sha1: de7615a94f5f3532531c7a8f7246a65407e06974
sha256: db7e2c547dfa7eb11e7bf9e637450bc9e8bee45898998cc879d1f31eb950ae68
sha512: 90153eba07dac170dc8490030adf25c70773bd877d3ee8e0a7ff83d90a801bdc5b4c8157a383a7c091e109f2fce5a95435c5c46277d08a5257a545671b346064
ssdeep: 6144:3FZwK0OqFNLVJ6S0lE+6LVjlWPuEwTIwMe/wwUQO:3zyhNLVJ/nLVjlWPuEwc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15844C62772D0F33AE121C6F5695993B4852EBC3116C6A807F6C12F1A77B2DA7A231317
sha3_384: e9b0c64cbab698ad5480820f054ec2141caabd4c74424142dbe2e9bf050f4fa3a2ff955d25315a6e263972b867e4b43a
ep_bytes: 68ac4a4000e8eeffffff000000000000
timestamp: 2012-10-13 18:27:31

Version Info:

Translation: 0x0409 0x04b0
ProductName: Croupiness
FileVersion: 6.53
ProductVersion: 6.53
InternalName: Silvanus
OriginalFilename: Silvanus.exe

Trojan.Win32.Jorik.Vobfus.gdcp also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.mepT
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.950
ClamAVWin.Packer.VBCrypt-5731517-0
CAT-QuickHealTrojan.Beebone.D
McAfeeGenDownloader.rv
MalwarebytesVBObfus.Worm.Spreader.DDS
ZillyaTrojan.Jorik.Win32.1004091
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Jorik.80eead5e
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.b9199c
BitDefenderThetaAI:Packer.EC9831A520
VirITTrojan.Win32.Generic.CKRZ
CyrenW32/Vobfus.BE.gen!Eldorado
SymantecW32.Changeup
ESET-NOD32a variant of Win32/VBObfus.CZ
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Jorik.Vobfus.gdcp
BitDefenderGen:Variant.Barys.950
NANO-AntivirusTrojan.Win32.Barys.cinaxh
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-AETI [Trj]
TencentTrojan.Win32.Jorik.co
TACHYONTrojan/W32.VB-Jorik.270336.E
EmsisoftGen:Variant.Barys.950 (B)
BaiduWin32.Worm.Pronny.d
F-SecureTrojan.TR/Barys.2655987
DrWebTrojan.DownLoader7.7390
VIPREGen:Variant.Barys.950
TrendMicroWORM_VOBFUS.SMJA
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dm
FireEyeGeneric.mg.e22e4d4b9199cb2e
SophosMal/SillyFDC-W
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Barys.950
JiangminWorm/Vobfus.ivb
AviraTR/Barys.2655987
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.Pronny.EE@4qvpy8
ArcabitTrojan.Barys.950
ViRobotWorm.Win32.A.Vobfus.270336
ZoneAlarmTrojan.Win32.Jorik.Vobfus.gdcp
MicrosoftWorm:Win32/Vobfus.gen!X
GoogleDetected
AhnLab-V3Trojan/Win32.Menti.R27300
VBA32BScope.Trojan.Diple
ALYacGen:Variant.Barys.950
MAXmalware (ai score=80)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMJA
RisingWorm.Win32.WBNA.r (CLASSIC)
IkarusTrojan.Win32.Otran
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-AETI [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Jorik.Vobfus.gdcp?

Trojan.Win32.Jorik.Vobfus.gdcp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment