Trojan

Trojan-Dropper.Win32.Dapato.qtef removal guide

Malware Removal

The Trojan-Dropper.Win32.Dapato.qtef is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Dapato.qtef virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Executed a command line with /V argument which modifies variable behaviour and whitespace allowing for increased obfuscation options
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location

How to determine Trojan-Dropper.Win32.Dapato.qtef?


File Info:

name: 9CBE980A0C93B6BD8D04.mlw
path: /opt/CAPEv2/storage/binaries/fee3974de04abf9a35a76dbe27dd0cdda9337f57b9a456ae18d0881ff3366d08
crc32: 83112C3E
md5: 9cbe980a0c93b6bd8d048673acabc0e6
sha1: bc2319496f8a749f97407e3b700bf7bd726e38b2
sha256: fee3974de04abf9a35a76dbe27dd0cdda9337f57b9a456ae18d0881ff3366d08
sha512: f59292290d9c8e5a34a40d066f365f08794175dd3cf393cf9c53cc72f9a40b7ddcc1ea4e6658e2294a83bf723103ef0e66a128379b0c5b9e6a9bc7ae43165211
ssdeep: 196608:dnoQ7+JmcIBWXdWXGr3jBZ7mLs8cP35jL215g:VoCsgXut8cP1o5g
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T17476339EBD6545A1E4F5003E2A1C22BE83F19E21F3C4D5A79F780E83B941CC96A6C375
sha3_384: 15bbde36784f495a28cf6657dfbd017d94f6056695b270560c97e9a3cf3975a06c5012465f06447a083434d156c334a2
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2019-07-30 08:52:45

Version Info:

FileVersion: 1.0.0.0
FileDescription: Mo7tarif PC
CompanyName: Advanced SystemCare 14 Crack
Translation: 0x0000 0x04e4

Trojan-Dropper.Win32.Dapato.qtef also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Encoder.trrL
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36904486
FireEyeGeneric.mg.9cbe980a0c93b6bd
ALYacTrojan.GenericKD.36904486
CylanceUnsafe
SangforTrojan.Win32.Dapato.qtef
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZexaF.34062.@x0@aKJbdgc
CyrenW32/Trojan.ICTN-6897
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
KasperskyTrojan-Dropper.Win32.Dapato.qtef
BitDefenderTrojan.GenericKD.36904486
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.36904486
EmsisoftTrojan.GenericKD.36904486 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SophosGeneric PUA LM (PUA)
GDataTrojan.GenericKD.36904486
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.2B9E7F9
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FT.A!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4296819
McAfeeArtemis!9CBE980A0C93
VBA32TrojanDropper.Dapato
APEXMalicious
RisingTrojan.Generic@ML.100 (RDML:JmGng79cjrxKlkhp/R7LRA)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat.PALLAS.H
AVGWin32:Malware-gen
PandaTrj/Genetic.gen

How to remove Trojan-Dropper.Win32.Dapato.qtef?

Trojan-Dropper.Win32.Dapato.qtef removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment