Trojan

Trojan:Win32/Dorv.C!rfn (file analysis)

Malware Removal

The Trojan:Win32/Dorv.C!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Dorv.C!rfn virus can do?

  • Network activity detected but not expressed in API logs

How to determine Trojan:Win32/Dorv.C!rfn?


File Info:

crc32: FF1F20EC
md5: bbfe021c880c6fb1fd39d042339e6d73
name: BBFE021C880C6FB1FD39D042339E6D73.mlw
sha1: 243b5be034516d5537af9f42fa3e62aedb54396f
sha256: 7b9f86c296625006d0d6347f40e7e824a537b112b9a788c95f638bd022334729
sha512: 44c227739ad81cbb1b455d5fb8ff7551c51a88e8023fe32bef1a77e0e1cdb8206a80d8c97fc1119abcead185ef3e7737e33ae690e3a58edaeb2092ca37461245
ssdeep: 6144:Nv0bAyEvLE9Wwn6PHd0HmsZUiojOoPtu/90iKXat1AI7v:F01EvL4jY0HeNo/uiKqbN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 1999-2013 Cortado AG
InternalName: TPAutoConnect
FileVersion: 8,8,774,1
CompanyName: C o rtado AG
ProductName: TPAutoConnect
ProductVersion: 8,8,774,1
FileDescription: ThinPrint AutoConnect component
OriginalFilename: TPAutoConnect.exe
Translation: 0x0409 0x04b0

Trojan:Win32/Dorv.C!rfn also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.Cerber.1
FireEyeGeneric.mg.bbfe021c880c6fb1
CAT-QuickHealRansom.Cerber.YY4
McAfeeGenericRXDI-GG!BBFE021C880C
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004f87f21 )
BitDefenderTrojan.Ransom.Cerber.1
K7GWTrojan ( 004f87f21 )
Cybereasonmalicious.c880c6
BitDefenderThetaGen:NN.ZexaF.34590.Cq1@aS8Si5Bi
CyrenW32/S-3e1d46f2!Eldorado
SymantecPacked.Generic.459
ESET-NOD32Win32/Filecoder.Cerber.B
BaiduWin32.Trojan.Cerber.h
APEXMalicious
AvastWin32:Filecoder-BG [Trj]
ClamAVWin.Ransomware.Razy-7997331-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Cerber.2495c986
NANO-AntivirusTrojan.Win32.Encoder.evdbmt
TencentMalware.Win32.Gencirc.10b558b4
Ad-AwareTrojan.Ransom.Cerber.1
EmsisoftTrojan.Ransom.Cerber.1 (B)
ComodoTrojWare.Win32.Kryptik.ERJ@6l0vie
F-SecureHeuristic.HEUR/AGEN.1121406
DrWebTrojan.Encoder.4691
ZillyaTrojan.Zerber.Win32.301
TrendMicroRansom_HPCERBER.SM30
McAfee-GW-EditionGenericRXDI-GG!BBFE021C880C
SophosML/PE-A + Mal/Cerber-B
IkarusTrojan.Crypt
JiangminTrojan.Zerber.vb
AviraHEUR/AGEN.1121406
MAXmalware (ai score=100)
Antiy-AVLTrojan[Ransom]/Win32.Zerber
MicrosoftTrojan:Win32/Dorv.C!rfn
ArcabitTrojan.Ransom.Cerber.1
AhnLab-V3Win-Trojan/Cerber.Gen
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.Cerber.1
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Trojan.Downloader
ALYacTrojan.Ransom.Cerber.1
MalwarebytesMalware.AI.2454176477
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPCERBER.SM30
RisingRansom.Cerber!8.3058 (C64:YzY0OnDRfoqX4o0c)
YandexTrojan.GenAsa!YCiVRZt7sdY
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_96%
FortinetW32/Kryptik.HEKH!tr
AVGWin32:Filecoder-BG [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Ransom.Cerber.HxQBRBYA

How to remove Trojan:Win32/Dorv.C!rfn?

Trojan:Win32/Dorv.C!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment