Trojan

How to remove “Trojan.Win32.Diple.dmof”?

Malware Removal

The Trojan.Win32.Diple.dmof is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Diple.dmof virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Diple.dmof?


File Info:

name: 56FEEE9B43A13AE9B817.mlw
path: /opt/CAPEv2/storage/binaries/5261eaf8b00542d99fbbe72ef3967ac32bf5f7ee0909dec9ddd05c6a2e7b165d
crc32: A54B33BD
md5: 56feee9b43a13ae9b817e649e88cc05e
sha1: 6cf9326e3375eee92b96ac344cbd65ddbffe5b1d
sha256: 5261eaf8b00542d99fbbe72ef3967ac32bf5f7ee0909dec9ddd05c6a2e7b165d
sha512: 00f35e9392b5995fc2406a2f1d144464d2e44f68b919b4601a8eb3c58d4d54fab7dbf5552e13336545afafc1cceb00917d46970afc1b23425193be812929dda9
ssdeep: 6144:JziYa2v8yCrmZHKnvmb7/D26jCEwC+9Zuuh7wmwbO8uRPe5H:WcnkmZHKnvmb7/D263uh7NwbO8S4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FB741A13EB21E05FD58198F22D2DA65D29261D3A66A2AC0332C1BF1C69719D7BCF074F
sha3_384: e45b9043ccda8b06a07ede2f26f38240b7e67708e60e78347eb033a0802d14ebb0a7a7cf5d92c18a909d3ab660a7661e
ep_bytes: 68243b4000e8eeffffff000000000000
timestamp: 1996-08-21 21:32:15

Version Info:

0: [No Data]

Trojan.Win32.Diple.dmof also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.low6
DrWebTrojan.VbCrypt.81
MicroWorld-eScanTrojan.GenericKDZ.95825
FireEyeGeneric.mg.56feee9b43a13ae9
CAT-QuickHealWorm.WbnaVMF.S20099144
ALYacTrojan.GenericKDZ.95825
MalwarebytesMalware.AI.1802172179
VIPRETrojan.GenericKDZ.95825
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.b43a13
BitDefenderThetaGen:NN.ZevbaF.36250.vmX@aOneq@c
VirITWorm.Win32.Generic.BDRM
CyrenW32/Vobfus.AA.gen!Eldorado
SymantecW32.Changeup!gen35
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.ANR
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyTrojan.Win32.Diple.dmof
BitDefenderTrojan.GenericKDZ.95825
NANO-AntivirusTrojan.Win32.WBNA.csfhjt
AvastWin32:VB-ZZI [Trj]
TencentMalware.Win32.Gencirc.10beae65
SophosMal/SillyFDC-T
F-SecureTrojan.TR/Patched.Ren.Gen
BaiduWin32.Worm.Autorun.l
TrendMicroWORM_VOBFUS.SMAB
McAfee-GW-EditionBehavesLike.Win32.VBObfus.fm
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKDZ.95825 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.95825
JiangminTrojan.Diple.amoh
GoogleDetected
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=81)
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.VB.AUB@4ol77w
ArcabitTrojan.Generic.D17651
ZoneAlarmTrojan.Win32.Diple.dmof
MicrosoftWorm:Win32/Vobfus.gen!O
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VBNA.R119870
Acronissuspicious
McAfeeArtemis!56FEEE9B43A1
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMAB
RisingWorm.VobfusEx!1.99E8 (CLASSIC)
YandexTrojan.GenAsa!4c71USf47CA
IkarusWorm.Win32.Vobfus
FortinetW32/VB.ADV!tr
AVGWin32:VB-ZZI [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Diple.dmof?

Trojan.Win32.Diple.dmof removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment