Trojan

What is “Trojan:Win32/Dorifel.EC!MTB”?

Malware Removal

The Trojan:Win32/Dorifel.EC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Dorifel.EC!MTB virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Dorifel.EC!MTB?


File Info:

name: F355ABF289A9D3042F42.mlw
path: /opt/CAPEv2/storage/binaries/ccc3d0f23ae17a7492d5217b89977bff793cf3a3664c959a0645d6f238879539
crc32: 33AD0A42
md5: f355abf289a9d3042f4296ee21d6510c
sha1: 5e1dad24319839429caa9bd0e019f6a9769b2c4b
sha256: ccc3d0f23ae17a7492d5217b89977bff793cf3a3664c959a0645d6f238879539
sha512: a979baf4086c302b1e9d6281e82c50b75e6d159d095719a49a799733ae8ba6713a7e4b9bbece1687c3c4cdaf4a9929eb7301c13cbef5130f2ce7df5e2c498a20
ssdeep: 49152:sxX7665YxRVplZzSK3tlGIiT+HvRdpMAHSjpjK3bB3BvbS:sxX7QnxbloE5dpkpMb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11ED53AE2B633C12BCC3337B5471B8BC42A55AE54216698BB33BA6B4E67747803D1D706
sha3_384: 8242e2bf1c1a315baa8ca340dffcc6f0fcfe4cbe87782eea4f3eb061b3573acb8bdc028658d95fcc21c3c37aa1bf908c
ep_bytes: c605e094570000b900d06600ba04d066
timestamp: 1970-01-01 00:00:00

Version Info:

FileDescription: System Devices Optimizer
InternalName: Devices Optimus
ProductName: Devices Optimus
ProductVersion: 7.0.0.0
Comments:
CompanyName:
FileVersion: 7.0.0.0
LegalCopyright:
LegalTrademarks:
OriginalFilename:
Translation: 0x0409 0x04e4

Trojan:Win32/Dorifel.EC!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.425169
CAT-QuickHealTrojan.GenericPMF.S30216659
McAfeeGenericRXVX-OC!F355ABF289A9
MalwarebytesGeneric.Trojan.Delf.DDS
VIPREGen:Variant.Barys.425169
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a1fa31 )
K7GWTrojan ( 005a1fa31 )
CrowdStrikewin/malicious_confidence_70% (W)
CyrenW32/Delf.VQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Delf.UYZ
CynetMalicious (score: 99)
BitDefenderGen:Variant.Barys.425169
NANO-AntivirusTrojan.Win32.Dorifel.jvyhwy
AvastWin32:DropperX-gen [Drp]
TencentTrojan-Dropper.Win32.Dorifel.he
EmsisoftGen:Variant.Barys.425169 (B)
F-SecureTrojan.TR/Redcap.msdyd
DrWebTrojan.MulDrop22.41593
ZillyaDropper.Dorifel.Win32.66808
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.f355abf289a9d304
SophosTroj/Delf-HPL
IkarusTrojan.Win32.Delf
JiangminTrojanDropper.Dorifel.basj
AviraTR/Redcap.msdyd
Antiy-AVLTrojan/Win32.Delf
MicrosoftTrojan:Win32/Dorifel.EC!MTB
ArcabitTrojan.Barys.D67CD1
ZoneAlarmUDS:Trojan.Win32.Agent
GDataWin32.Trojan.PSE.15A4KQ3
GoogleDetected
AhnLab-V3Dropper/Win.Generic.R575943
ALYacGen:Variant.Barys.425169
MAXmalware (ai score=83)
VBA32TrojanDropper.Dorifel
PandaTrj/Genetic.gen
RisingTrojan.Delf!1.E833 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Delf.UYZ!tr
AVGWin32:DropperX-gen [Drp]

How to remove Trojan:Win32/Dorifel.EC!MTB?

Trojan:Win32/Dorifel.EC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment