Trojan

Trojan.Win32.Jorik.Vobfus.gtqf removal

Malware Removal

The Trojan.Win32.Jorik.Vobfus.gtqf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Jorik.Vobfus.gtqf virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Win32.Jorik.Vobfus.gtqf?


File Info:

name: 1287F7B6DCA04C52260A.mlw
path: /opt/CAPEv2/storage/binaries/34a2bf94c40e267117149cfee75be004b1bb8b05b29bdbd670d3cc3f6b5aecb9
crc32: 6F2D1B12
md5: 1287f7b6dca04c52260accdf44a2e726
sha1: f06fd28c92ed768f5504f063e25e5e65c490e93d
sha256: 34a2bf94c40e267117149cfee75be004b1bb8b05b29bdbd670d3cc3f6b5aecb9
sha512: 8d85030896d68d7a42c9081d5799a62c453ad7926e9dfda71653258d003929bcd2a7b85e88faacc29c74c73f1a405dbdf053a83d1603971c77bc9b14e438c314
ssdeep: 3072:SR4r6dJvRtFD1yPBYEmaHtGG2gqZ+/9A+JRjKY5Md41gfl6J:7uh1yPptGG2gqZ+FfKqDsq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C244626963A0B73DE820C1F868875360846DED331895A40BEBD2771676F0DA7F3207A7
sha3_384: df8569520a53095ec143a59f0cf7cb313f0e01a467c4b9d004ecaeb87eb06f6649ac18afc2c4224a8e90d594846780c0
ep_bytes: 6810414000e8f0ffffff000000000000
timestamp: 2012-03-28 19:53:28

Version Info:

ProductName:
FileVersion: 1.00
ProductVersion: 1.00
InternalName:
OriginalFilename:
Translation: 0x0409 0x04b0

Trojan.Win32.Jorik.Vobfus.gtqf also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.950
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
ALYacGen:Variant.Barys.950
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
ArcabitTrojan.Barys.950
BaiduWin32.Trojan.Inject.n
VirITTrojan.Win32.VB.TO
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/AutoRun.VB.ATZ
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMIJ
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyTrojan.Win32.Jorik.Vobfus.gtqf
BitDefenderGen:Variant.Barys.950
NANO-AntivirusTrojan.Win32.Jorik.cmtits
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-ACAA [Trj]
TencentWorm.Win32.Vobfus.n
TACHYONTrojan/W32.VB-Jorik.253952.C
EmsisoftGen:Variant.Barys.950 (B)
F-SecureWorm.WORM/Vobfus.R.100
DrWebTrojan.VbCrypt.60
VIPREGen:Variant.Barys.950
TrendMicroWORM_VOBFUS.SMIJ
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.1287f7b6dca04c52
SophosMal/SillyFDC-W
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Diple.Gen
GoogleDetected
AviraWORM/Vobfus.R.100
VaristW32/Vobfus.AD.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.Pronny.AK@4ogvoo
MicrosoftWorm:Win32/Vobfus!pz
ViRobotWorm.Win32.A.WBNA.253952.CBK
ZoneAlarmTrojan.Win32.Jorik.Vobfus.gtqf
GDataGen:Variant.Barys.950
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R22928
Acronissuspicious
McAfeeGeneric VB.kk
MAXmalware (ai score=89)
VBA32Trojan.VB.MTA.01636
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.GEW.worm
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!fcdBOcOOr18
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
BitDefenderThetaGen:NN.ZevbaF.36804.pm0@aKOOXzei
AVGWin32:VB-ACAA [Trj]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.84a61f34

How to remove Trojan.Win32.Jorik.Vobfus.gtqf?

Trojan.Win32.Jorik.Vobfus.gtqf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment