Trojan

About “Trojan.Worgtop” infection

Malware Removal

The Trojan.Worgtop is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Worgtop virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to modify UAC prompt behavior

How to determine Trojan.Worgtop?


File Info:

name: D5C24D8C2EDA8A50C754.mlw
path: /opt/CAPEv2/storage/binaries/b3e16a03c16bf081197ac493cf2de68150c5ef880ce80cee164e6d115d421e9f
crc32: 9BD1B735
md5: d5c24d8c2eda8a50c7541fec171cf67c
sha1: cc108c1f40436e7c21e6ec9fdd25d58166028d4d
sha256: b3e16a03c16bf081197ac493cf2de68150c5ef880ce80cee164e6d115d421e9f
sha512: 0192e12d3aed05395b4ca8244e64ad63d72212730acf91fd00038c92e4910b461c03abe22db2ef3bf1cb4b56a1a24d0199d4b8731d21acf4a4f7a46da7b10d3a
ssdeep: 49152:So1RcrPKK1YmXee5EyImpiQtbiSMAwUwBZV5F4bmwY30MGF4ZhdR+:Sy0qkePkiQtbiS7wZt4bu09F4n+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T148A533923E8F6F14F49AED7A5FCE7E811716803C66AD2382F5EECA3E1521C81725119C
sha3_384: 51bbf3692bed12294d230291c92d9874c963111189200e1964450577e3489983a56c981f621228cd8e3897fadf97838f
ep_bytes: 60be004065008dbe00d0daff5783cdff
timestamp: 2021-09-01 19:59:29

Version Info:

FileDescription:
FileVersion: 1.0.0.0
ProgramID:
ProductName:
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04e4

Trojan.Worgtop also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Worgtop.d!c
DrWebTrojan.PWS.Growtopia.57
MicroWorld-eScanGen:Heur.Variadic.A.200.1
FireEyeGeneric.mg.d5c24d8c2eda8a50
CAT-QuickHealTrojan.Worgtop
ALYacGen:Heur.Variadic.A.200.1
MalwarebytesSpyware.PasswordStealer.Growtopia
ZillyaTrojan.Growtopia.Win32.3206
K7AntiVirusPassword-Stealer ( 0058006d1 )
AlibabaTrojan:Win32/Starter.ali2000005
K7GWPassword-Stealer ( 0058006d1 )
Cybereasonmalicious.c2eda8
BitDefenderThetaGen:NN.ZexaF.34084.boKfaSXxBQfi
CyrenW32/Growtopia.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.Growtopia.U
TrendMicro-HouseCallTROJ_GEN.R002C0PL421
Paloaltogeneric.ml
KasperskyHEUR:Trojan-GameThief.Win32.Worgtop.gen
BitDefenderGen:Heur.Variadic.A.200.1
AvastWin32:PWSX-gen [Trj]
TencentWin32.Trojan-gamethief.Worgtop.Wstm
Ad-AwareGen:Heur.Variadic.A.200.1
EmsisoftGen:Heur.Variadic.A.200.1 (B)
TrendMicroTROJ_GEN.R002C0PL421
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosMal/Generic-S
IkarusTrojan-PSW.Growtopia
JiangminTrojan.PSW.Worgtop.aa
AviraHEUR/AGEN.1145046
Antiy-AVLTrojan/Generic.ASMalwS.34953A8
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.GrowtopiaStealer.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.GameThief.R433376
McAfeeArtemis!D5C24D8C2EDA
MAXmalware (ai score=82)
VBA32TrojanPSW.Growtopia
APEXMalicious
YandexTrojan.PWS.Growtopia!3qJ4BQv/rzc
SentinelOneStatic AI – Malicious PE
FortinetW32/Growtopia.I!tr.pws
AVGWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Worgtop?

Trojan.Worgtop removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment