Worm

Worm:Win32/Dorkbot.A removal guide

Malware Removal

The Worm:Win32/Dorkbot.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Dorkbot.A virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Code injection with CreateRemoteThread in a remote process
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates known Ruskill mutexes
  • Creates a copy of itself

How to determine Worm:Win32/Dorkbot.A?


File Info:

crc32: 3B7257DC
md5: a928f97f6b48c803201aefb573e9b096
name: A928F97F6B48C803201AEFB573E9B096.mlw
sha1: c61f03ef59cd07a66684bc1dcef746e998028fcf
sha256: dcdc2184402f628d6da7a839915441c1224a5542f4d277460ab2084f9d540481
sha512: d24cd8dfe550a83bcb49b8b99cfb4d4c5d28c7cb769d247939f253e0ef3322de1eab525f5a8b507ee6390c766e3b572cd3cc02c74304993f6b6150ccd036c969
ssdeep: 6144:X32wFTU3QSU5ntuxR8EYJ6lbqsYskRJCVef3:X32wi3QdFtuH8EdlbqOHef3
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0409 0x04b0
InternalName: MagicDisc1
FileVersion: 2.07.0106
CompanyName: MagicISO, Inc.
ProductName: MagicDisc
ProductVersion: 2.07.0106
OriginalFilename: MagicDisc1.exe

Worm:Win32/Dorkbot.A also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.2382
FireEyeGeneric.mg.a928f97f6b48c803
McAfeeArtemis!A928F97F6B48
CylanceUnsafe
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Barys.2382
K7GWTrojan ( 004bcce41 )
K7AntiVirusTrojan ( 004bcce41 )
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:VB-ABSB [Trj]
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.NgrBot.eijrcw
TencentWin32.Trojan.Jorik.Llqu
Ad-AwareGen:Variant.Barys.2382
SophosMal/Generic-S
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebBackDoor.IRC.NgrBot.42
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.MoonLight.fm
EmsisoftGen:Variant.Barys.2382 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.dzdgu
WebrootW32.Malware.Gen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftWorm:Win32/Dorkbot.A
ArcabitTrojan.Barys.D94E
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Barys.2382
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.NgrBot.C238886
Acronissuspicious
VBA32SScope.Trojan.VBRA.3878
ALYacGen:Variant.Barys.2382
MAXmalware (ai score=86)
MalwarebytesMalware.Heuristic.1003
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Injector.PBA
RisingWorm.Dorkbot!8.1B4 (TFE:5:PNmvwv5ByOQ)
YandexTrojan.GenAsa!G8wx2LtP67o
IkarusTrojan.Win32.Ircbrute
FortinetW32/PolyPatch.UPX!tr
BitDefenderThetaGen:NN.ZevbaF.34804.tm0@aGMCZIii
AVGWin32:VB-ABSB [Trj]
Paloaltogeneric.ml
Qihoo-360HEUR/Malware.QVM03.Gen

How to remove Worm:Win32/Dorkbot.A?

Worm:Win32/Dorkbot.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment