Trojan

How to remove “Trojan.DNSChanger”?

Malware Removal

The Trojan.DNSChanger is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.DNSChanger virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.DNSChanger?


File Info:

name: C0E6D9F400422F665A77.mlw
path: /opt/CAPEv2/storage/binaries/9be3483f3666f9c89c42f7ac1681e3f9afb42a62cab179b215734524482cdb10
crc32: 897F9917
md5: c0e6d9f400422f665a779358c530d7a4
sha1: 1fee689ddb041f0c86e0f1c39fd17580e227ddde
sha256: 9be3483f3666f9c89c42f7ac1681e3f9afb42a62cab179b215734524482cdb10
sha512: 7eca6bb6ae815e2d78fd51bb41f6b40471c37c6c0061acb718712ec1a7494bd9fb146c77c7f9058347a64172a390df09b96b82e4aed8eb80c474725d5e877d4d
ssdeep: 6144:L6W1pm33F+p+PDqbRmk8JCYcOYxFQ0PacWSdv5cHUFOz3+4ZmTmAEkmdLs+fBu/O:L6WvmMp+okfcBFmcNdxcHUFi3+AmTmXZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12FE47C46FF1310F5DC434A300297F76F2BACE271B0A09B6ED6450E25DE671F4AA2E256
sha3_384: 70e01459bc034c05f21a27ef4dbea9360d8e136b1ba49a4e44a2418f32547684c6b44484242568cb0df3be89177f540c
ep_bytes: 83ec1cc7042402000000ff1548b54500
timestamp: 1971-08-12 15:21:44

Version Info:

0: [No Data]

Trojan.DNSChanger also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.59701
FireEyeGeneric.mg.c0e6d9f400422f66
McAfeeGenericRXRB-FQ!C0E6D9F40042
CylanceUnsafe
K7AntiVirusTrojan ( 0055a0b81 )
K7GWTrojan ( 0055a0b81 )
Cybereasonmalicious.400422
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/DNSChanger.NEA
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Raidon.gen
BitDefenderGen:Variant.Bulz.59701
AvastWin32:Trojan-gen
TencentWin32.Trojan.Raidon.Syrm
Ad-AwareGen:Variant.Bulz.59701
SophosML/PE-A + Mal/Swrort-Y
McAfee-GW-EditionBehavesLike.Win32.Backdoor.bm
EmsisoftGen:Variant.Bulz.59701 (B)
IkarusTrojan.Win32.DNSChanger
AviraTR/Redcap.jjfgv
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Bulz.59701
CynetMalicious (score: 99)
BitDefenderThetaGen:NN.ZexaF.34062.ROZ@aKH37jo
ALYacGen:Variant.Bulz.59701
MAXmalware (ai score=82)
MalwarebytesTrojan.DNSChanger
TrendMicro-HouseCallTROJ_GEN.R002H0CL721
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/DNSChanger.NEA!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.DNSChanger?

Trojan.DNSChanger removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment