Worm

How to remove “Worm:Win32/Ganelp!rfn”?

Malware Removal

The Worm:Win32/Ganelp!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Ganelp!rfn virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Worm:Win32/Ganelp!rfn?


File Info:

name: 9B89DA5C4C3D161A9B1E.mlw
path: /opt/CAPEv2/storage/binaries/3196c4607f582011666328f361ff00516c908c5ae2f8285ab9f1f06c1d6cfe0d
crc32: C1B72690
md5: 9b89da5c4c3d161a9b1eb9fd1a917449
sha1: 8cdcac96b1feb03519fd9cbf9b0569585bd031ce
sha256: 3196c4607f582011666328f361ff00516c908c5ae2f8285ab9f1f06c1d6cfe0d
sha512: 3405c6a5aac91cabb04cf5e91d67ba31bfd543cb5256c6b876580cc7b269d4857179a24be6e111fecdb3f63f5dac0e8f6c63a9c9385a00b9fb25f03b34fb4b3f
ssdeep: 768:BvQB0ESOGg1UrYShBbgrrMo98l4yOoBDqANhhY/4El6BhGUVTnbcuyD7UN:BvQBeOGtrYS3srx93UBWfwC6Ggnouy8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DA13E1D0202B63CCE0FE217D7949F5051951516AF9A08FE67BE88497E820F71C4EDABE
sha3_384: 5066040a95cde714bf12cb67d21e36872272383cf167c45c564235007ceafa5eb41b0c0746876acdd595e9775182e3fe
ep_bytes: 60be00b041008dbe0060feff5789e58d
timestamp: 2015-01-27 03:56:27

Version Info:

0: [No Data]

Worm:Win32/Ganelp!rfn also known as:

BkavW32.FamVT.DinwoodAATTC.Worm
LionicTrojan.Win32.Dinwod.tn6p
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.71491
FireEyeTrojan.GenericKDZ.71491
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeGenericRXMR-EG!9B89DA5C4C3D
MalwarebytesTrojan.Dropper
ZillyaDropper.DinwodGen.Win32.2
AlibabaWorm:Win32/Ganelp.44d
Cybereasonmalicious.c4c3d1
BaiduWin32.Trojan.Agent.acb
CyrenW32/Risk.VLIE-3898
SymantecTrojan Horse
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Dinwod-9828955-0
BitDefenderTrojan.GenericKDZ.71491
AvastWin32:Bladabindi-AL [Trj]
TencentTrojan.Win32.Dinwod.ya
Ad-AwareTrojan.GenericKDZ.71491
EmsisoftTrojan.GenericKDZ.71491 (B)
ComodoTrojWare.Win32.TrojanDropper.Dinwod.A@5vqtjo
DrWebTrojan.Inject1.58305
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DGE21
McAfee-GW-EditionBehavesLike.Win32.Generic.pc
SophosTroj/Eydrop-A
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.71491
JiangminTrojanDropper.Dinwod.ale
AviraTR/Spy.Gen
GridinsoftRansom.U.Bladabindi.sa
ArcabitTrojan.Generic.D11743
ViRobotTrojan.Win32.Agent.69310
MicrosoftWorm:Win32/Ganelp!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.OnlineGameHack.C33730
Acronissuspicious
ALYacTrojan.GenericKDZ.71491
MAXmalware (ai score=88)
TrendMicro-HouseCallTROJ_GEN.R002C0DGE21
YandexTrojan.DR.Dinwod!8URa/WHFPDk
eGambitUnsafe.AI_Score_100%
FortinetW32/CoinMiner.BBYK!tr
AVGWin32:Bladabindi-AL [Trj]
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Worm:Win32/Ganelp!rfn?

Worm:Win32/Ganelp!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment