Trojan

TrojanDropper:Win32/Dinome.A removal tips

Malware Removal

The TrojanDropper:Win32/Dinome.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Dinome.A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

redirector.gvt1.com
r8—sn-bpb5oxu-3c2r.gvt1.com
update.googleapis.com

How to determine TrojanDropper:Win32/Dinome.A?


File Info:

crc32: 6BF1DABE
md5: 0660193b88814f300036536d1629464f
name: 0660193B88814F300036536D1629464F.mlw
sha1: 9863bca42272bb63d8d8cb2f2c3cfc445ab085d4
sha256: e96cc1f27a33ec291476b1b0850352ea9c7dd42677865ef7d0d5d8b937f89b40
sha512: adc19f3e8861e2d28c9aee1c0d9cdd9268925a8442e6e387d747b0fd258bfafdd8650d722c9fb5bb404da0f35a6624c53ea369b51bbf55565062697a677341fc
ssdeep: 768:TManite22/E7X5gzoy/qna3BImTia+Vx2RL9kFiVKfW4IW4LAUYZfY7eh:TM8itel0JXy/qnaRxkVx2x9kFiMu4IV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xCKklwIl
InternalName: 9qz7uA
FileVersion: fzUbSKI7ZlZ
CompanyName: Hex-Rays SA
ProductName: YEwesWVt6
ProductVersion: WdalH3N16k
FileDescription: I9NT
OriginalFilename: Ol71JMttnV5hm

TrojanDropper:Win32/Dinome.A also known as:

K7AntiVirusTrojan ( 002daab61 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop2.42471
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Ransom.A
ALYacGen:Variant.Kazy.493
CylanceUnsafe
ZillyaTrojan.Timer.Win32.1966
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/Obfuscator.e5f3d211
K7GWTrojan ( 002daab61 )
Cybereasonmalicious.b88814
CyrenW32/Ransom.J.gen!Eldorado
SymantecPacked.Mystic!gen8
ESET-NOD32a variant of Win32/Kryptik.QDD
APEXMalicious
AvastWin32:Ransom [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Kazy.493
NANO-AntivirusTrojan.Win32.Drop.bgytnu
SUPERAntiSpywareTrojan.Agent/Gen-Perpeton
MicroWorld-eScanGen:Variant.Kazy.493
TencentWin32.Trojan.Timer.cku
Ad-AwareGen:Variant.Kazy.493
SophosMal/Generic-S + Mal/EncPk-ADY
ComodoTrojWare.Win32.Trojan.Agent.~xtsa@3ymfaa
BitDefenderThetaGen:NN.ZexaF.34688.cu0@ayxzqgpg
VIPRETrojan.Win32.Ransom.dp (v)
TrendMicroTROJ_GEN.F43EZIH
McAfee-GW-EditionFakeAV-SecurityTool.cv
FireEyeGeneric.mg.0660193b88814f30
EmsisoftGen:Variant.Kazy.493 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
AviraTR/Crypt.ZPACK.Gen
eGambitGeneric.Malware
MicrosoftTrojanDropper:Win32/Dinome.A
ArcabitTrojan.Kazy.493
AegisLabTrojan.Win32.Timer.j!c
GDataGen:Variant.Kazy.493
TACHYONTrojan/W32.Timer.44544.K
Acronissuspicious
McAfeeFakeAV-SecurityTool.cv
MAXmalware (ai score=100)
VBA32Trojan.ExpProc.014
MalwarebytesMachineLearning/Anomalous.100%
PandaGeneric Malware
TrendMicro-HouseCallTROJ_GEN.F43EZIH
RisingRansom.Genasom!8.293 (CLOUD)
YandexTrojan.Timer!ZV+N8hMWnaY
IkarusTrojan-Ransom.Timer
FortinetW32/RansomTimer.fam!tr
AVGWin32:Ransom [Trj]
Paloaltogeneric.ml

How to remove TrojanDropper:Win32/Dinome.A?

TrojanDropper:Win32/Dinome.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment