Trojan

Trojan-Dropper.Win32.Dorifel removal guide

Malware Removal

The Trojan-Dropper.Win32.Dorifel is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Dorifel virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • Attempts to execute a binary from a dead or sinkholed URL
  • Installs itself for autorun at Windows startup
  • Detects VirtualBox through the presence of a registry key

Related domains:

dlied6.qq.com
www.52popsoft.com

How to determine Trojan-Dropper.Win32.Dorifel?


File Info:

crc32: 2F714ECD
md5: b39cece4ba445dfc7348c285b7492ce9
name: B39CECE4BA445DFC7348C285B7492CE9.mlw
sha1: 3a7c231886fa09c485bd8552b152354bc69a3c30
sha256: 242d1b5609a0ffd6fe6d58a527a5d0d51f90600cb9813bfdd74fe91570ad6e9d
sha512: fea0e1b68578f02787cc194d899d2409655dcfb1643117e6cdb00ee914a207c9569f01a9d88db725b5018a41168971dea1bec64a0e8430c5056cad62f13850b7
ssdeep: 24576:Os8pMNpEirFWI+UneqZw7VeTCL56p9CqR8T3R+JrkuURVok4XoOEKJxca:Os8pToFWRoeqCeTCUp/Ru099s0f/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: PopCalculator
FileVersion: 1.0.0.0
CompanyName: x5927x4f17x8f6fx4ef6
Comments: PopCalculator
ProductName: PopCalculator
ProductVersion: 1.0.0.0
FileDescription: PopCalculator
Translation: 0x0804 0x04b0

Trojan-Dropper.Win32.Dorifel also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005246d51 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader23.40334
CynetMalicious (score: 100)
CAT-QuickHealTrojandropper.Dorifel
ALYacGen:Variant.Application.Graftor.460754
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.103132
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:Win32/Inject.abb7b6f7
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.4ba445
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Score-6912404-0
KasperskyHEUR:Trojan-Dropper.Win32.Dorifel.gen
BitDefenderGen:Variant.Application.Graftor.460754
NANO-AntivirusTrojan.Win32.Agent.ehudbd
MicroWorld-eScanGen:Variant.Application.Graftor.460754
TencentWin32.Trojan.Generic.Pezk
Ad-AwareGen:Variant.Application.Graftor.460754
SophosMal/Generic-S
ComodoWorm.Win32.Dropper.RA@1qraug
BitDefenderThetaGen:NN.ZexaF.34236.zr0@amKjTghb
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0OGB21
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.b39cece4ba445dfc
EmsisoftGen:Variant.Application.Graftor.460754 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Generic.annf
WebrootW32.Trojan.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.148EACD
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Tiggre!rfn
ZoneAlarmHEUR:Trojan-Dropper.Win32.Dorifel.gen
GDataWin32.Trojan.PSE.11B5R9D
AhnLab-V3Malware/Gen.Generic.C1111205
Acronissuspicious
McAfeeArtemis!B39CECE4BA44
VBA32Trojan-Inject.Memtest
MalwarebytesTrojan.MalPack.FlyStudio
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0OGB21
RisingTrojan.Generic@ML.99 (RDML:O1hY7NccvRNSqqTn8CwTig)
YandexTrojan.GenAsa!yuyVX/J4uT8
IkarusTrojan.Win32.Tiggre
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.65CA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Dropper.Win32.Dorifel?

Trojan-Dropper.Win32.Dorifel removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment