Trojan

How to remove “Trojan:Win32/Dinwod!pz”?

Malware Removal

The Trojan:Win32/Dinwod!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Dinwod!pz virus can do?

  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Dinwod!pz?


File Info:

name: F80980D4DE780A4166F4.mlw
path: /opt/CAPEv2/storage/binaries/276fabe6bce625f7fa1d225f24f2c291e608baa027762e1365257dc1ae02e52b
crc32: F2986DAA
md5: f80980d4de780a4166f4320adff95243
sha1: 4ed96a8c445de5405521d37a328c7fe87df523b1
sha256: 276fabe6bce625f7fa1d225f24f2c291e608baa027762e1365257dc1ae02e52b
sha512: 693b07271edaecc2181b84e24a879ff780b6a25f9bda811c9023846be4990523c114887fa76be5a3052153b5bfa8bc98c2f8f9352693cfc78e628bd4eb5e0632
ssdeep: 12288:PXgvmzFHi0mo5aH0qMzd58T7FTxPJQPDHvd:PXgvOHi0mGaH0qSdYFP4V
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15076AF76B681C8F2C4858032769D6E136DF9AC300934AA67DB54CF092EF55E9D32E34B
sha3_384: feeef9ec7b0e8258249f06f20396df13d8ac986a317f81a801f04d63d3a6de0de6bd2723367fb66ef67381b633ee7f91
ep_bytes: 6a6068f8b74200e8edf7ffffbf940000
timestamp: 2006-12-09 06:24:20

Version Info:

0: [No Data]

Trojan:Win32/Dinwod!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Blocker.tnDI
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.AgentWDCR.JMO
FireEyeGeneric.mg.f80980d4de780a41
CAT-QuickHealWorm.Pykspa.C3
SkyhighBehavesLike.Win32.Pykse.wz
McAfeeW32/Pykse.worm.gen.a
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Blocker.Win32.28137
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 003da8d71 )
AlibabaMalware:Win32/km_28a2.None
K7GWTrojan ( 003da8d71 )
Cybereasonmalicious.c445de
BitDefenderThetaGen:NN.ZexaF.36744.@pW@aKVW8Lo
VirITTrojan.Win32.AntiAV.PIN
SymantecW32.Pykspa.D
ESET-NOD32Win32/AutoRun.Agent.TG
APEXMalicious
ClamAVWin.Worm.Autorun-437
KasperskyHEUR:Worm.Win32.Agent.gen
BitDefenderTrojan.AgentWDCR.JMO
NANO-AntivirusTrojan.Win32.AntiAV.dsnxsg
AvastWin32:Renos-KY [Trj]
TencentWorm.Win32.Yah.za
TACHYONWorm/W32.Yah.7565312
EmsisoftTrojan.AgentWDCR.JMO (B)
BaiduWin32.Worm.Autorun.o
F-SecureTrojan.TR/Agent.327680.A
DrWebTrojan.Kypes.2
VIPRETrojan.AgentWDCR.JMO
TrendMicroTROJ_AGENT_006376.TOMB
Trapminemalicious.high.ml.score
SophosW32/Pykse-H
IkarusTrojan.Agent
GDataWin32.Trojan.BSE.1JWSKP9
JiangminWorm.Yah.h
WebrootWorm:Win32/Pykspa.C
GoogleDetected
AviraTR/Agent.327680.A
VaristW32/Pykspa.A.gen!Eldorado
Antiy-AVLTrojan/Win32.AntiAV
XcitiumWorm.Win32.Autorun.Agent_TG0@1isiwy
ArcabitTrojan.AgentWDCR.JMO
ViRobotTrojan.Win32.Blocker.Gen.B
ZoneAlarmHEUR:Worm.Win32.Agent.gen
MicrosoftTrojan:Win32/Dinwod!pz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zepfod.R4378
Acronissuspicious
VBA32Worm.Yah
ALYacTrojan.AgentWDCR.JMO
MAXmalware (ai score=84)
Cylanceunsafe
PandaW32/SpySkype.E
ZonerTrojan.Win32.24407
TrendMicro-HouseCallTROJ_AGENT_006376.TOMB
RisingWorm.Autorun!1.BC87 (CLASSIC)
YandexWorm.Yah!+rU5F30BDN4
SentinelOneStatic AI – Malicious PE
MaxSecureBackdoor.Zepfod.A
FortinetW32/AutoRun.AGENT.AUA!tr
AVGWin32:Renos-KY [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Dinwod!pz?

Trojan:Win32/Dinwod!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment