Trojan

Trojan-Dropper.Win32.Dapato.qtrc information

Malware Removal

The Trojan-Dropper.Win32.Dapato.qtrc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Dapato.qtrc virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known windows from debuggers and forensic tools
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Dropper.Win32.Dapato.qtrc?


File Info:

crc32: C2D20539
md5: 095aa6b7f53f1ede045809fb62cfdc79
name: 095AA6B7F53F1EDE045809FB62CFDC79.mlw
sha1: 52f1e20a91e73a1a12654321464e294dc957b801
sha256: a13a0192437981f6d2c3fc19dfa0f0d4ce4ab2be96ffbccfec87c29bc2f200c7
sha512: 03b476bd409e6f765dd9f4bebb8d75bc97b6836d98b22a6ad9b42548fb37f4de76358db631bab5a077e425ef83ea1557246ca89265561f9711f031068ff6ca9e
ssdeep: 196608:Uts0XFN3CWhD+8pWLcIIoZx2UEPNRjVVZ+wiuZ3jvGugkGjuNcfhpCRNxGfAod7K:Jmf3phvUZvEPNRVHrpZ3Nf+hpCRNxGfU
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: TorrentFreedom
FileDescription: Adobe.snr.patch.v2.0 1.5.1 Installation
FileVersion: 1.5.1
Comments:
CompanyName: TorrentFreedom
Translation: 0x0409 0x04e4

Trojan-Dropper.Win32.Dapato.qtrc also known as:

K7AntiVirusUnwanted-Program ( 004d8e041 )
SangforTrojan.Win32.Dapato.qtrc
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojanDropper:Win32/Dapato.4e0c700d
K7GWUnwanted-Program ( 004d8e041 )
Cybereasonmalicious.a91e73
CyrenW32/Trojan.LXFT-6263
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/HackTool.Patcher.CH potentially unsafe
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Crack-6988654-0
KasperskyTrojan-Dropper.Win32.Dapato.qtrc
TencentWin32.Trojan-dropper.Dapato.Fig
SophosGeneric PUA FC (PUA)
VIPREHackTool.Win32.Keygen
McAfee-GW-EditionBehavesLike.Win32.PUP.vc
MicrosoftHackTool:Win32/Keygen
AhnLab-V3Malware/Win.Generic.C4544412
McAfeeArtemis!095AA6B7F53F
TrendMicro-HouseCallTROJ_GEN.R002H07G721
MaxSecureTrojan-Ransom.Win32.Crypmod.zfq
FortinetW32/Malicious_Behavior.VEX
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Heur.Generic.HwUBXBIB

How to remove Trojan-Dropper.Win32.Dapato.qtrc?

Trojan-Dropper.Win32.Dapato.qtrc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment