Trojan

About “Trojan.Win32.Diztakun.btpx” infection

Malware Removal

The Trojan.Win32.Diztakun.btpx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Diztakun.btpx virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Win32.Diztakun.btpx?


File Info:

name: 1763F7D63E4D5621E994.mlw
path: /opt/CAPEv2/storage/binaries/0beb17a6456c11bd7fc5a24b70f72c7e3fea13af7f2e7dc86d40ae1bee4180f7
crc32: 48644F71
md5: 1763f7d63e4d5621e99456fed08cf039
sha1: 176118ac020455120b8bfee09c2d63a0ac645baf
sha256: 0beb17a6456c11bd7fc5a24b70f72c7e3fea13af7f2e7dc86d40ae1bee4180f7
sha512: 4d6e6ed7e41b351bbd5e1951c5ebe82a4cb96be7097cbeda8f1381b04023cb681fd0dbf66050db019daeccaaf573f619368a200bfb246020779db30dbc0d5f96
ssdeep: 12288:KNc/FBwaU7N8qA4fEf32oykAF8R1hcgd0zUJ3hfRxMk71IMbbuoSBt/MNJZ06jxx:8cPaBfsVR1hUKh0k71XbbC406jxhAlcj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T184F412527360EA46C3B20DF2DC1ED72421606E2D071A6E0F37B7BB1E48B7341B966A5D
sha3_384: d23f1cbb9c0765a843c6c881576674846f4ed9556028bbac2385b2c567f61737f1904a40765c19a68c2772864550c3e8
ep_bytes: 60be004056008dbe00d0e9ffc787a440
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName:
FileDescription:
FileVersion: 1.0.0.0
InternalName: tester
LegalCopyright:
LegalTrademarks:
OriginalFilename: tester
ProductName:
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04e4

Trojan.Win32.Diztakun.btpx also known as:

LionicTrojan.Win32.Diztakun.4!c
MicroWorld-eScanTrojan.GenericKD.46959804
McAfeeArtemis!1763F7D63E4D
CylanceUnsafe
SangforTrojan.Win32.Diztakun.btpx
BitDefenderTrojan.GenericKD.46959804
CyrenW32/Hupigon.CG.gen!Eldorado
SymantecTrojan.Gen.MBT
Paloaltogeneric.ml
KasperskyTrojan.Win32.Diztakun.btpx
AlibabaTrojan:Win32/Diztakun.b99dc619
Ad-AwareTrojan.GenericKD.46959804
EmsisoftTrojan.GenericKD.46959804 (B)
ZillyaTrojan.Agent.Win32.1185170
TrendMicroTROJ_GEN.R035C0WIK21
SophosMal/Generic-S
APEXMalicious
JiangminTrojan.Qhost.fd
AviraTR/Diztakun.vkmrf
MAXmalware (ai score=83)
ArcabitTrojan.Generic.D2CC8CBC
MicrosoftTrojan:Win32/Wacatac.A!ml
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.46959804
MalwarebytesMalware.Heuristic.1003
PandaTrj/CI.A
TencentWin32.Trojan.Diztakun.Dxwt
FortinetW32/Diztakun.BTPX!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Trojan.Win32.Diztakun.btpx?

Trojan.Win32.Diztakun.btpx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment