Backdoor

Backdoor:Win32/Ditertag.A removal tips

Malware Removal

The Backdoor:Win32/Ditertag.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Ditertag.A virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • Performs some HTTP requests
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Collects information to fingerprint the system

Related domains:

cutit.org

How to determine Backdoor:Win32/Ditertag.A?


File Info:

crc32: CFEE1D87
md5: 7e5f1720f6a68475a2028d6a24cf5410
name: 7E5F1720F6A68475A2028D6A24CF5410.mlw
sha1: 8bd99262cbee53e9eb9d7f4a828e88937a1554de
sha256: bbaa648af2cdc5a0e8bb47795a749c3dcbdae9dc4fce16bebf3a96a0a09da043
sha512: 3f457646587f95b1709c33da58cf8147c97eee978fa810d991aa5b50518fae79dbca10ff8c401600d8a99133b5366bc2cb0c2de652a788169b65fdd3f10f90c8
ssdeep: 12288:mbI9ssdHdAEgfKSj5Bcl3qfXJEgkns3IiSU78NFGim9GkaL2AOpmY4IEi:dSUHEbjQl3qf5rkn2pZ72EiEaSOYfP
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Backdoor:Win32/Ditertag.A also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004bcce41 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.771482
CylanceUnsafe
ZillyaTrojan.Injector.Win32.997067
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaMalware:Win32/km_280b22.None
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.0f6a68
CyrenW32/Kryptik.DND.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
AvastWin32:Trojan-gen
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.771482
MicroWorld-eScanGen:Variant.Razy.771482
TencentMalware.Win32.Gencirc.11c4c5a5
Ad-AwareGen:Variant.Razy.771482
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaAI:Packer.5711E2911E
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R049C0RG521
McAfee-GW-EditionBehavesLike.Win32.Generic.dm
FireEyeGeneric.mg.7e5f1720f6a68475
EmsisoftGen:Variant.Razy.771482 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.gvhia
AviraTR/Crypt.ULPM.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASBOL.C687
MicrosoftBackdoor:Win32/Ditertag.A
GDataGen:Variant.Razy.771482
TACHYONTrojan/W32.Agent.966656.ARP
AhnLab-V3Malware/Win32.RL_Generic.R370211
McAfeeGenericRXAA-FA!7E5F1720F6A6
MAXmalware (ai score=80)
VBA32BScope.Trojan.Wacatac
MalwarebytesSpyware.PasswordStealer
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R049C0RG521
RisingTrojan.Kryptik!1.D12D (CLASSIC)
YandexTrojan.Agent!Lez41RtEuYE
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Backdoor:Win32/Ditertag.A?

Backdoor:Win32/Ditertag.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment