Trojan

Trojan.Win32.TorJok.lv removal guide

Malware Removal

The Trojan.Win32.TorJok.lv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.TorJok.lv virus can do?

  • Injection (inter-process)
  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • A potential decoy document was displayed to the user
  • Creates a hidden or system file
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
nodejs.org
www.torproject.org
dist.torproject.org
redirector.gvt1.com
r4—sn-4g5ednsy.gvt1.com

How to determine Trojan.Win32.TorJok.lv?


File Info:

crc32: 207AF8C1
md5: f6d5246abdd434a24a6739869eaac132
name: upload_file
sha1: 8b20babe972f580f1b8f4aca4f7724f7866a595a
sha256: 75fa551eec71d6d8b9817266813715c2bbb7a537005587f9f1e0d058a05febc6
sha512: 2e0e467e57426bbb2dae7253f6fb56aa1877af17ce6cc29f68665c0bf0c0e972f818c54a5a8c341859433bbc4b947fb9986627225263694666ee8aae00e2463f
ssdeep: 12288:LCp0jH/Op7j0hxSSJPBS27lGm4sxIHXC6Pu1LoGHFCZRlIzF/+WWPFDpIY:LCp0jfON0KSJPBpBx3qHXC6Pu1EGHFCb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.TorJok.lv also known as:

MicroWorld-eScanTrojan.GenericKD.34366866
FireEyeGeneric.mg.f6d5246abdd434a2
ALYacTrojan.Torjok.gen
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.34366866
K7GWRiskware ( 0040eff71 )
Invinceaheuristic
SymantecTrojan.Gen.MBT
APEXMalicious
KasperskyTrojan.Win32.TorJok.lv
AlibabaTrojan:Win32/TorJok.56281e0f
TencentWin32.Trojan.Torjok.Efkn
Ad-AwareTrojan.GenericKD.34366866
ComodoTrojWare.Win32.Agent.xzokn@0
F-SecureTrojan.TR/Torjok.elgkq
DrWebJS.Siggen5.40263
FortinetW32/TorJok.LV!tr
SophosMal/Generic-S
AviraTR/Torjok.elgkq
ArcabitTrojan.Generic.D20C6592
ZoneAlarmTrojan.Win32.TorJok.lv
MicrosoftTrojan:Win32/Ymacco.AA75
CynetMalicious (score: 85)
McAfeeArtemis!F6D5246ABDD4
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H09HG20
RisingTrojan.ScriptRunner!1.CA86 (CLASSIC)
GDataTrojan.GenericKD.34366866
AVGWin32:Malware-gen
AvastWin32:Malware-gen
Qihoo-360Win32/Trojan.a7a

How to remove Trojan.Win32.TorJok.lv?

Trojan.Win32.TorJok.lv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment