Trojan

Trojan.Win32.Diztakun.brft removal tips

Malware Removal

The Trojan.Win32.Diztakun.brft is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Diztakun.brft virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family

How to determine Trojan.Win32.Diztakun.brft?


File Info:

name: 17E2222457579D92F743.mlw
path: /opt/CAPEv2/storage/binaries/1dca2b36d1c433b2473c19d24b3ad2e3fa02f3621b72a6894aa35bd49c21cca1
crc32: 820D5452
md5: 17e2222457579d92f743eb3d0ac82433
sha1: 26db63402bef440ec5c5cea2e48ceafbc2278f76
sha256: 1dca2b36d1c433b2473c19d24b3ad2e3fa02f3621b72a6894aa35bd49c21cca1
sha512: 3c516be4237eced1a96f143d8fd5621c00e9e3200bd2e6f0d97b8bc2b5664cd731b3209628beb4fd802d6bb8844fbfe7d34797dc640ebc93fd9faa567c13b5e6
ssdeep: 6144:eDKW1Lgbdl0TBBvjc/p2iaU1Dyl3UPMReHIK+K+DKx6j4dp0L:4h1Lk70TnvjchEYDyuPoE6EdO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15164E02471D1C1B3C4B7113484E5CA765A7930720B7A95DBB79C2BBA6F123E1A3362CE
sha3_384: 06cd65198714558e38e5c65c1bcf231ab83f201f192dac2e5fb8afe05943f85d138dc6466e506fcc7393eb486ba5a242
ep_bytes: e8e15c0000e9a4feffff8bff558bec83
timestamp: 2012-07-13 22:47:16

Version Info:

Translation: 0x0000 0x04b0
CompanyName: etkilit
FileDescription: Usbkey Kilit Programi
FileVersion: 1.9.0.2
InternalName: etkilit.exe
LegalCopyright:
LegalTrademarks: Güvenlik Duvarı Hizmetleri
OriginalFilename: etkilit.exe
ProductName: etkilit
ProductVersion: 1.9.0.2
Assembly Version: 1.9.0.2

Trojan.Win32.Diztakun.brft also known as:

LionicTrojan.Win32.Diztakun.4!c
DrWebTrojan.MulDrop15.61202
MicroWorld-eScanTrojan.GenericKD.44582892
FireEyeTrojan.GenericKD.44582892
McAfeeArtemis!17E222245757
CylanceUnsafe
ZillyaTrojan.Diztakun.Win32.6964
SangforTrojan.Win32.ClipBanker.mt
AlibabaTrojan:Win32/Diztakun.377c95c4
BitDefenderThetaGen:NN.ZemsilF.34212.uq0@aCaF0Ep
SymantecML.Attribute.HighConfidence
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Diztakun.brft
BitDefenderTrojan.GenericKD.44582892
NANO-AntivirusTrojan.Win32.Diztakun.ifnmtv
Ad-AwareTrojan.GenericKD.44582892
SophosGeneric ML PUA (PUA)
VIPRETrojan.Win32.Generic!BT
EmsisoftTrojan.GenericKD.44582892 (B)
Paloaltogeneric.ml
GDataWin32.Trojan.Sabsik.B
AviraTR/Diztakun.aiqas
ZoneAlarmTrojan.Win32.Diztakun.brft
MicrosoftBackdoor:Win32/Bladabindi!ml
VBA32Trojan.Diztakun
ALYacTrojan.GenericKD.44582892
MAXmalware (ai score=82)
APEXMalicious
RisingTrojan.Diztakun!8.FE (CLOUD)
MaxSecureTrojan.Malware.300983.susgen
FortinetMalicious_Behavior.SB
AVGFileRepMalware
Cybereasonmalicious.457579
PandaTrj/CI.A

How to remove Trojan.Win32.Diztakun.brft?

Trojan.Win32.Diztakun.brft removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment