Trojan

How to remove “Trojan.DorvPMF.S31807803”?

Malware Removal

The Trojan.DorvPMF.S31807803 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.DorvPMF.S31807803 virus can do?

  • Reads data out of its own binary image
  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.DorvPMF.S31807803?


File Info:

name: 5458B9777540BE9545CD.mlw
path: /opt/CAPEv2/storage/binaries/854209dc8e7f615f4e97b2de3c94a3e823d3d7432b0bc466c9d9d4774978fd5f
crc32: 43CEBA86
md5: 5458b9777540be9545cd4594c25593e1
sha1: 7567e6252744092f22d74747c43c27234c5ec296
sha256: 854209dc8e7f615f4e97b2de3c94a3e823d3d7432b0bc466c9d9d4774978fd5f
sha512: 66338c3144611a12773527c236756c655901ea5b0395fb2ee341a562363e14ac39da4d36d39df4758545b924ea27cad78e8492f276bc07878d1c74f1c57aa77e
ssdeep: 12288:i2ToLD2QfWUEknSsmjj/UVF4T2SddLTnTjMVJK1P5aEL3XHyhxoeVsc:ikuPfWsnnw/UV+2Sddv/MVcRag2v1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T154255C3AAF8A9136D97234BC8C5FC1D4941D39312C585B87FF816F4C7E76642236AA83
sha3_384: a0c67b06de8e1f8e2594f585c95462e55e5b7123586acf897a3c912249fffef95ee62dacfebb28270475b2f0557ea68f
ep_bytes: 558bec83c4f05356b81c991100e83ad3
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Work Connection
FileDescription: Net Driver Connection
FileVersion: 1.0.0.61
InternalName:
LegalCopyright:
LegalTrademarks: Work Connection
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Translation: 0x0416 0x04e4

Trojan.DorvPMF.S31807803 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.308797
FireEyeGeneric.mg.5458b9777540be95
CAT-QuickHealTrojan.DorvPMF.S31807803
SkyhighBehavesLike.Win32.Generic.dh
ALYacGen:Variant.Zusy.308797
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Zusy.308797
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 004bfe9d1 )
K7GWSpyware ( 004bfe9d1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZelphiF.36802.8G0@auv89coG
VirITTrojan.Win32.Banker6.CIJ
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Banker.WGA
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Netmail-9844910-0
KasperskyBackdoor.Win32.NetMail.a
BitDefenderGen:Variant.Zusy.308797
NANO-AntivirusTrojan.Win32.NetMail.cndhca
SUPERAntiSpywareTrojan.Agent/Gen-SpyBanker
AvastWin32:Evo-gen [Trj]
TACHYONTrojan/W32.DP-Agent.988160
SophosTroj/Agent-BCNT
F-SecureTrojan.TR/Zusy.9881605548
DrWebTrojan.DownLoader4.61273
ZillyaTrojan.Banker.Win32.53195
TrendMicroBackdoor.Win32.NETMAIL.SMTH
EmsisoftGen:Variant.Zusy.308797 (B)
IkarusTrojan-Banker.Win32.Delf
GDataWin32.Trojan-Stealer.Banker.AK
JiangminBackdoor/NetMail.a
VaristW32/Banker.V.gen!Eldorado
AviraTR/Zusy.9881605548
Antiy-AVLTrojan[Backdoor]/Win32.NetMail
XcitiumTrojWare.Win32.Spy.Banker.VIS@8ekceg
ArcabitTrojan.Zusy.D4B63D
ZoneAlarmBackdoor.Win32.NetMail.a
MicrosoftTrojan:Win32/Dorv.B!rfn
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.C64982
MAXmalware (ai score=81)
VBA32Backdoor.NetMail
Cylanceunsafe
PandaTrj/Dtcontx.I
ZonerTrojan.Win32.88740
TrendMicro-HouseCallBackdoor.Win32.NETMAIL.SMTH
RisingRansom.Blocker!8.12A (KTSE)
YandexBackdoor.NetMail!pG6fLhj3QoI
SentinelOneStatic AI – Malicious PE
FortinetW32/AGen.Z!tr.spy
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.77540b
DeepInstinctMALICIOUS

How to remove Trojan.DorvPMF.S31807803?

Trojan.DorvPMF.S31807803 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment