Trojan

Trojan.Win32.Dapta removal instruction

Malware Removal

The Trojan.Win32.Dapta is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Dapta virus can do?

  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Harvests cookies for information gathering
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Dapta?


File Info:

name: 9F4B65AF80ED935F71B9.mlw
path: /opt/CAPEv2/storage/binaries/e0b1fb028534a87a911da3cbdef0c0b92be0b6857da55912a07f132109616b4a
crc32: 81FA6C3D
md5: 9f4b65af80ed935f71b9a9fdbd0314e0
sha1: 9ebb6e52cc559feedc2cd3b9390964bf50eb327f
sha256: e0b1fb028534a87a911da3cbdef0c0b92be0b6857da55912a07f132109616b4a
sha512: 61524afe4b1c9371fe42540c891aca8e17441185bf91d1492cb3a1065d1ccd0334936587401436fc7e60e1b2181d7257c3ac46db32ec28a11aff891b2328af1d
ssdeep: 12288:YIOiHJ6Lmb2+/GaBfnpkIDo3i9Yuq0MPeq0i7+ASRJ5J:YIDk+ZZnpktYiXSRfJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A9B4CF681E9DCC4EC2925D785AF2E22DE1BADD215C2E461BDF127DC9AF36BC83D41042
sha3_384: 1fc70a75f712ff404d075e481f6fe1fd181aaf4cf32a8a1eb9f33f2948c035889bbe430da16c47fe1232c958c5e2d017
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2016-07-25 00:55:47

Version Info:

CompanyName: 广州忆游未尽网络科技有限公司
FileVersion: 3.0.0.1028
ProductName: 三国群英传
ProductVersion: 3.0.0.1028
Translation: 0x0804 0x03a8

Trojan.Win32.Dapta also known as:

LionicTrojan.Win32.Dapta.4!c
MicroWorld-eScanTrojan.GenericKD.48039354
FireEyeTrojan.GenericKD.48039354
McAfeeArtemis!9F4B65AF80ED
CylanceUnsafe
SangforTrojan.Win32.Dapta.gen
CyrenW32/Trojan.UNIY-3608
tehtrisGeneric.Malware
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Dapta.gen
BitDefenderTrojan.GenericKD.48039354
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.48039354
SophosMal/Generic-S
DrWebTrojan.MulDrop18.60219
ZillyaTrojan.Dapta.Win32.259
TrendMicroTROJ_GEN.R002C0PDO22
McAfee-GW-EditionBehavesLike.Win32.Dropper.hh
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.48039354 (B)
GDataTrojan.GenericKD.48039354
AviraTR/Redcap.kcmlo
MAXmalware (ai score=81)
MicrosoftTrojan:Win32/Wacatac.B!ml
VBA32Trojan.Dapta
ALYacTrojan.GenericKD.48039354
TrendMicro-HouseCallTROJ_GEN.R002C0PDO22
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove Trojan.Win32.Dapta?

Trojan.Win32.Dapta removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment