Trojan

Trojan:Win32/Dingu.A (file analysis)

Malware Removal

The Trojan:Win32/Dingu.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Dingu.A virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Trojan:Win32/Dingu.A?


File Info:

name: EFA1ADD763EEF93E8D75.mlw
path: /opt/CAPEv2/storage/binaries/4bc36bb02603ea155a0fe441e6fc8b169af8a56f82ad37074fcaa80639f0bad1
crc32: 5B8E00F1
md5: efa1add763eef93e8d759b090bfe518e
sha1: 5176f6e28de61e3df56a01e0757a34a94e2896c0
sha256: 4bc36bb02603ea155a0fe441e6fc8b169af8a56f82ad37074fcaa80639f0bad1
sha512: 44267582e087a2dd7659553dc0f9a24dfd26f8bb7904e03f186fd67ebd60befb2042ae6959783b9da5d58f6b1aef3e1fd8cf0e1cbb876f96e7d1e93a3753ae43
ssdeep: 768:VgH8wIMiU9ZlLodfJyInttO7Uc0b1XhbNK1RM7QVobt55VUMHFFxm:m8rU9rodJyItt31XvKM7QMNFFxm
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T17A334A07AB8150F1DA412BB8305B677B993F69A4724AA7D38F3BCEB45873220F13D245
sha3_384: 955512d3b55473809d4b41f7eecb0c25db27b4ab7aa6b2a36b7aa1e97962b0648e98b29a6df80ccaa6cba18b39dab637
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2014-09-18 00:20:30

Version Info:

0: [No Data]

Trojan:Win32/Dingu.A also known as:

BkavW32.Common.828B39E3
LionicTrojan.Win32.Dingu.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.44852
SkyhighBehavesLike.Win32.Ransomware.qh
McAfeeRDN/Generic.dx
ZillyaTrojan.BlackGear.Win32.56
SangforSuspicious.Win32.Save.ins
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojan:Win32/Dingu.1e77a9a9
K7GWRiskware ( 00584baa1 )
ArcabitTrojan.Doina.DAF34
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0DAG24
ClamAVWin.Trojan.Terminatorat-1
KasperskyHEUR:Trojan.Win32.BlackGear.gen
BitDefenderGen:Variant.Doina.44852
NANO-AntivirusTrojan.Win32.Dingu.dibbbb
AvastWin32:Malware-gen
EmsisoftGen:Variant.Doina.44852 (B)
VIPREGen:Variant.Doina.44852
TrendMicroTROJ_GEN.R002C0DAG24
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.efa1add763eef93e
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=82)
GoogleDetected
Antiy-AVLTrojan/Win32.Dingu
Kingsoftmalware.kb.a.998
MicrosoftTrojan:Win32/Dingu.A
ZoneAlarmHEUR:Trojan.Win32.BlackGear.gen
GDataGen:Variant.Doina.44852
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZedlaF.36804.dq4@aalO10b
ALYacGen:Variant.Doina.44852
VBA32BScope.Trojan-Dropper.Inject
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Dingu!8.1FFD (CLOUD)
IkarusTrojan.Win32.Dingu
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Dingu.A

How to remove Trojan:Win32/Dingu.A?

Trojan:Win32/Dingu.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment