Trojan

Trojandropper.Dorifel removal instruction

Malware Removal

The Trojandropper.Dorifel is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojandropper.Dorifel virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

How to determine Trojandropper.Dorifel?


File Info:

crc32: 23099258
md5: e6b09168e2019017c0cffe88044588aa
name: drop.bin
sha1: c15692fcf6c009d47e4b9928af500fd0f593ecc1
sha256: 948c1dc3e09d84f90499e0d47b5344e112ee6ea8da850b973472932d880bf306
sha512: 483a34bdf7af9229b74aeb2577209d004ff59332246cacb64f1111bfdccd383e2f5c522fc587a551f29e88ad85a4f654f9cc47ab70a29c948cda76e1ef10b337
ssdeep: 3072:KQy+bnr+O1q5GWp1icKAArDZz4N9GhbkrNEk1/j4soF:KQy+bnr+Bp0yN90QE+4j
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Wextract
FileVersion: 11.00.17763.1 (WinBuild.160101.0800)
CompanyName: Microsoft Corporation
ProductName: Internet Explorer
ProductVersion: 11.00.17763.1
FileDescription: Win32 Cabinet Self-Extractor
OriginalFilename: WEXTRACT.EXE .MUI
Translation: 0x0409 0x04b0

Trojandropper.Dorifel also known as:

MicroWorld-eScanGen:Heur.Crifi.3
FireEyeGen:Heur.Crifi.3
CAT-QuickHealTrojandropper.Dorifel
McAfeeRDN/Generic Dropper
CylanceUnsafe
AegisLabTrojan.Win32.Dorifel.b!c
SangforMalware
K7AntiVirusTrojan ( 005613b41 )
BitDefenderGen:Heur.Crifi.3
K7GWTrojan ( 005613b41 )
Cybereasonmalicious.8e2019
BitDefenderThetaAI:Packer.F9D653B223
ESET-NOD32a variant of Win32/Injector.EKTY
GDataGen:Heur.Crifi.3
KasperskyHEUR:Trojan-Dropper.Win32.Dorifel.vho
AlibabaTrojanDropper:Win32/GenKryptik.e186afcb
ViRobotTrojan.Win32.Z.Crifi.240128
RisingDropper.Dorifel!8.31E (CLOUD)
Ad-AwareGen:Heur.Crifi.3
SophosMal/Generic-S
F-SecureTrojan.TR/Dropper.VB.Gen
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.dm
EmsisoftGen:Heur.Crifi.3 (B)
APEXMalicious
CyrenW32/Trojan.DUDV-7343
AviraTR/Kryptik.tkeej
Endgamemalicious (high confidence)
ArcabitTrojan.Crifi.3
ZoneAlarmHEUR:Trojan-Dropper.Win32.Dorifel.vho
MicrosoftTrojan:Win32/Occamy.C
ALYacGen:Heur.Crifi.3
MAXmalware (ai score=88)
MalwarebytesTrojan.Dropper.WXT.Generic
PandaTrj/CI.A
TencentWin32.Trojan-dropper.Dorifel.Alsa
IkarusTrojan-Spy.Agent
FortinetW32/GenKryptik.EDRQ!tr
WebrootW32.Trojan.Gen
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.Dropper.528

How to remove Trojandropper.Dorifel?

Trojandropper.Dorifel removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment