Trojan

How to remove “Trojan.Win32.Diple.gvvj”?

Malware Removal

The Trojan.Win32.Diple.gvvj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Diple.gvvj virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Executed a sysinternals tool
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Diple.gvvj?


File Info:

name: 994E395743F2DE895DC2.mlw
path: /opt/CAPEv2/storage/binaries/ac7f9c536153780ccbec949f23b86f3d16e3105a5f14bb667df752aa815b0dc4
crc32: BD15078F
md5: 994e395743f2de895dc29e3878074257
sha1: d34ecb078535d521b5c6b49d3f5df30661d9dab8
sha256: ac7f9c536153780ccbec949f23b86f3d16e3105a5f14bb667df752aa815b0dc4
sha512: a2f1e113e0a289f499819ca36838a124d67a9cf2bea719598e016e354cd22a5d28b5b7d4614115109743fe52c2ff9fff4c626554066f57c188803db759f5dfca
ssdeep: 24576:rF8bvzqxxY1RBv+O3EqokUCdWh4SZ5NQ75olmeu5xU4Cd5IBGxyjsSKR/mjLzKZ:rF8bv/1fv+ZAsZ5NQ75olmrrmdCoTZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T196A56B1263E840AAF1B352719EBD8767E676BC720B31C6CF5694520E1F32EE15E34722
sha3_384: 70d6716e975b502c97bb9d96a103ae018e90d4eea0f228c98b64a460e8d950db1f44f8af6cb17001a7b42e0091813a31
ep_bytes: e8bcb00000e9000000006a1468407a4b
timestamp: 2017-04-30 23:09:08

Version Info:

CompanyName: Sysinternals - www.sysinternals.com
FileDescription: Process Monitor
FileVersion: 3.33
InternalName: Process Monitor
LegalCopyright: Copyright © 1996-2017 Mark Russinovich
OriginalFilename: Process Monitor
ProductName: Sysinternals Procmon
ProductVersion: 3.33
Translation: 0x0409 0x04b0

Trojan.Win32.Diple.gvvj also known as:

BkavW32.Common.7D6AD9F6
LionicTrojan.Win32.Diple.4!c
ClamAVWin.Trojan.DarkHydrus-6690441-0
FireEyeGeneric.mg.994e395743f2de89
SkyhighTrojan-FTOC!994E395743F2
McAfeeTrojan-FTOC!994E395743F2
Cylanceunsafe
ZillyaTrojan.Diple.Win32.92520
SangforTrojan.Win32.Diple.gvvj
AlibabaTrojan:Win32/Diple.37311e4e
Cybereasonmalicious.78535d
SymantecTrojan.Gen.6
ESET-NOD32a variant of Win32/Patched.IY
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Diple.gvvj
NANO-AntivirusTrojan.Win32.Diple.ffvlsx
AvastFileRepMalware [Trj]
TencentWin32.Trojan.Diple.Timw
TACHYONTrojan/W32.Diple.2124800
TrendMicroTROJ_FRS.0NA103AE20
SophosMal/Generic-S
IkarusExploit.CVE-2018-8120
JiangminTrojan.Diple.bopn
GoogleDetected
Antiy-AVLTrojan[APT]/Win32.Lazymeerkat
Kingsoftmalware.kb.a.722
ZoneAlarmTrojan.Win32.Diple.gvvj
MicrosoftTrojan:Win32/Casdet!rfn
AhnLab-V3Trojan/Win32.Shelma.C2636853
ALYacTrojan.Agent.Diple
VBA32Trojan.Diple
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Chgt.AB
TrendMicro-HouseCallTROJ_FRS.0NA103AE20
RisingTrojan.Diple!8.46B (KTSE)
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Patched.IY!tr
AVGFileRepMalware [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Diple.gvvj?

Trojan.Win32.Diple.gvvj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment