Worm

About “Worm.DorkBot” infection

Malware Removal

The Worm.DorkBot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.DorkBot virus can do?

  • Executable code extraction
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Worm.DorkBot?


File Info:

crc32: 488C19E4
md5: f9e66dd40ffbd53d2bd3642a6a8bc78e
name: F9E66DD40FFBD53D2BD3642A6A8BC78E.mlw
sha1: 8162d8c6ee9f824914356d50c15a7bc48c726559
sha256: 2f9707b08bca93f8aa41bd87418180166667d12654ad5fbd2a94162e987e815a
sha512: 98a878d5120b594cf37c4684c2807c667f3c4dee04387f6949cf152b2ce41861d1215a8dcfd149de74ad627e3489b48d82256b908558263f8fbd7a1e96d13426
ssdeep: 3072:3yhGrWfhllF9t6qz5KrI6+/W8+6Lf3vDXO:3yrhLF9t7+xFgD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0c0a 0x04b0
InternalName: Trimestret
FileVersion: 1.00
CompanyName: Propie
ProductName: Trimestret
ProductVersion: 1.00
OriginalFilename: Trimestret.exe

Worm.DorkBot also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004b8b021 )
LionicTrojan.Win32.Blocker.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.7485
CynetMalicious (score: 100)
ALYacTrojan.Generic.8199433
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.1932
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/Blocker.acd5a82c
K7GWTrojan ( 004b8b021 )
Cybereasonmalicious.40ffbd
CyrenW32/Worm.MCGV-0646
SymantecW32.IRCBot.NG
ESET-NOD32Win32/Dorkbot.B
ZonerTrojan.Win32.11992
APEXMalicious
AvastWin32:GenMalicious-YS [Trj]
ClamAVWin.Trojan.Ruskill-7592512-0
KasperskyTrojan-Ransom.Win32.Blocker.our
BitDefenderTrojan.Generic.8199433
NANO-AntivirusTrojan.Win32.TrjGen.covkiu
ViRobotTrojan.Win32.A.VBKrypt.53248.DF
MicroWorld-eScanTrojan.Generic.8199433
TencentMalware.Win32.Gencirc.114cb03a
Ad-AwareTrojan.Generic.8199433
ComodoMalware@#2pxaxwo9ksikf
BitDefenderThetaGen:NN.ZevbaF.34170.jm0@au1HNYG
VIPREWorm.Win32.Dorkbot
McAfee-GW-EditionBehavesLike.Win32.Sality.cm
FireEyeGeneric.mg.f9e66dd40ffbd53d
EmsisoftTrojan.Generic.8199433 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Blocker.kjn
WebrootW32.Malware.Gen
AviraTR/Spy.Zbot.EB.179
Antiy-AVLTrojan/Generic.ASMalwS.213BC8
MicrosoftWorm:Win32/Dorkbot.A
SUPERAntiSpywareTrojan.Agent/Gen-Vbkrypt
GDataTrojan.Generic.8199433
AhnLab-V3Backdoor/Win32.Ruskill.R47590
McAfeeGenericRXAA-AA!F9E66DD40FFB
MAXmalware (ai score=100)
VBA32BScope.Trojan.Agent
MalwarebytesWorm.DorkBot
PandaGeneric Malware
YandexTrojan.GenAsa!hx/iOtyxCQo
IkarusTrojan.Win32.Klovbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrpk.NBOT!tr
AVGWin32:GenMalicious-YS [Trj]
Paloaltogeneric.ml

How to remove Worm.DorkBot?

Worm.DorkBot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment