Trojan

Trojan.DorvPMF.S31807803 removal guide

Malware Removal

The Trojan.DorvPMF.S31807803 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.DorvPMF.S31807803 virus can do?

  • Reads data out of its own binary image
  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.DorvPMF.S31807803?


File Info:

name: CDCC6DEFF2145F4DCB09.mlw
path: /opt/CAPEv2/storage/binaries/30870e2b46a893b1f0fb2a6d49a3e37ebc130bd8e410410508325f5dc700efba
crc32: 06373E8D
md5: cdcc6deff2145f4dcb09cfd6058005af
sha1: 2f64f6f0c983d6b8908dd87de309c14bffd17614
sha256: 30870e2b46a893b1f0fb2a6d49a3e37ebc130bd8e410410508325f5dc700efba
sha512: 1cc043e5a5a78aec98083733fef790fb51cd9429fd1752dad3b6a2eefcb8dc0b55b7997d850ac80e6ef49efbd9a7a146de9a0c086992f846a58fa6ace308e284
ssdeep: 12288:i2ToLD2QfWUEknSsmjj/UVF4TPShB9pP1TjMVJK1P5aEL3SUyhxoeVsc:ikuPfWsnnw/UV+PShBDxMVcRai2v1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T142255B3BAF8A9136D96234BC4C5FC1D4981D39312C584B87FF819F4C7E76652236AA83
sha3_384: 1197692c0707b2a576f79ea4a3f89eaf0ca07b58569ee13cf0a4279fa4a7827d537a62ee2170668cfaceae4b11135904
ep_bytes: 558bec83c4f05356b81c991100e83ad3
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Work Connection
FileDescription: Net Driver Connection
FileVersion: 1.0.0.61
InternalName:
LegalCopyright:
LegalTrademarks: Work Connection
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Translation: 0x0416 0x04e4

Trojan.DorvPMF.S31807803 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Zusy.308797
FireEyeGeneric.mg.cdcc6deff2145f4d
CAT-QuickHealTrojan.DorvPMF.S31807803
SkyhighBehavesLike.Win32.Generic.dh
McAfeePWS-Banker.gen.ez
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Zusy.308797
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 004bfe9d1 )
K7GWSpyware ( 004bfe9d1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZelphiF.36744.8G0@auv89coG
VirITTrojan.Win32.Banker6.CIJ
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Banker.WGA
APEXMalicious
ClamAVWin.Trojan.Netmail-9844910-0
KasperskyBackdoor.Win32.NetMail.a
BitDefenderGen:Variant.Zusy.308797
NANO-AntivirusTrojan.Win32.NetMail.cndhca
SUPERAntiSpywareTrojan.Agent/Gen-SpyBanker
AvastWin32:Evo-gen [Trj]
SophosTroj/Agent-BCNT
F-SecureTrojan.TR/Zusy.9881605548
DrWebTrojan.DownLoader4.61273
ZillyaTrojan.Banker.Win32.53195
TrendMicroBackdoor.Win32.NETMAIL.SMTH
EmsisoftGen:Variant.Zusy.308797 (B)
IkarusTrojan-Banker.Win32.Delf
MAXmalware (ai score=87)
GDataWin32.Trojan-Stealer.Banker.AK
JiangminBackdoor/NetMail.a
GoogleDetected
AviraTR/Zusy.9881605548
VaristW32/Banker.V.gen!Eldorado
Antiy-AVLTrojan[Backdoor]/Win32.NetMail
Kingsoftmalware.kb.a.992
XcitiumTrojWare.Win32.Spy.Banker.VIS@8ekceg
ArcabitTrojan.Zusy.D4B63D
ZoneAlarmBackdoor.Win32.NetMail.a
MicrosoftTrojan:Win32/Dorv.B!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.C64982
VBA32Backdoor.NetMail
ALYacGen:Variant.Zusy.308797
TACHYONTrojan/W32.DP-Agent.988160
Cylanceunsafe
PandaTrj/Dtcontx.I
ZonerTrojan.Win32.88740
TrendMicro-HouseCallBackdoor.Win32.NETMAIL.SMTH
RisingRansom.Blocker!8.12A (KTSE)
YandexBackdoor.NetMail!pG6fLhj3QoI
SentinelOneStatic AI – Malicious PE
FortinetW32/AGen.Z!tr.spy
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.0c983d
DeepInstinctMALICIOUS

How to remove Trojan.DorvPMF.S31807803?

Trojan.DorvPMF.S31807803 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment