Trojan

Trojan:Win32/Dinwod!pz removal

Malware Removal

The Trojan:Win32/Dinwod!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Dinwod!pz virus can do?

  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Dinwod!pz?


File Info:

name: 177AE6304D02558C7BDF.mlw
path: /opt/CAPEv2/storage/binaries/c3cc1cb578658583592ad9aed211266cba57a7e6fa5b36a04d0665bae13a5036
crc32: 359319C1
md5: 177ae6304d02558c7bdfee094a10b6f9
sha1: c6d6b9643c5bda529514fe6e1df9fd1dea559fa8
sha256: c3cc1cb578658583592ad9aed211266cba57a7e6fa5b36a04d0665bae13a5036
sha512: 6164b081f5dd262fd88afbad7f0617470e6fb02df5c85077eab54bb840a26109b1d58eaaef3cb92491a104d9a72fb814961a53bbc7530c16e4b645cfc9bcc72b
ssdeep: 12288:HXgvmzFHi0mo5aH0qMzd58I7FzPJQPDHvd:HXgvOHi0mGaH0qSdvFV4V
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T173A5BF3AB680C8F1C481903276955E135EF5A8341614EE6BEBA0DE053EF61E4D72A3DF
sha3_384: cac7043097cc8bb53eefb414f53d212b2c89f5cec17f438788aac580e3a7855f8e0b93738b5dc473b6321affe22c7099
ep_bytes: 6a6068f8b74200e8edf7ffffbf940000
timestamp: 2006-12-09 08:53:27

Version Info:

0: [No Data]

Trojan:Win32/Dinwod!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.AgentWDCR.JMO
ClamAVWin.Worm.Autorun-437
CAT-QuickHealWorm.Pykspa.C3
SkyhighBehavesLike.Win32.Pykse.vz
McAfeeW32/Pykse.worm.gen.a
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Blocker.Win32.28137
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 003da8d71 )
K7GWTrojan ( 003da8d71 )
Cybereasonmalicious.43c5bd
BitDefenderThetaGen:NN.ZexaF.36744.goW@aGGKPDn
VirITTrojan.Win32.AntiAV.PIN
SymantecW32.Pykspa.D
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.Agent.TG
ZonerTrojan.Win32.24407
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Worm.Win32.Agent.gen
BitDefenderTrojan.AgentWDCR.JMO
NANO-AntivirusTrojan.Win32.AntiAV.dsnxsg
SUPERAntiSpywareWorm.SkypeBot
AvastWin32:Renos-KY [Trj]
TencentWorm.Win32.Yah.za
EmsisoftTrojan.AgentWDCR.JMO (B)
BaiduWin32.Worm.Autorun.o
F-SecureTrojan.TR/Agent.327680.A
DrWebTrojan.Kypes.2
VIPRETrojan.AgentWDCR.JMO
TrendMicroTROJ_AGENT_006376.TOMB
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.177ae6304d02558c
SophosW32/Pykse-H
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.BSE.1JWSKP9
JiangminWorm.Yah.h
WebrootWorm:Win32/Pykspa.C
GoogleDetected
AviraTR/Agent.327680.A
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.AntiAV
XcitiumWorm.Win32.Autorun.Agent_TG0@1isiwy
ArcabitTrojan.AgentWDCR.JMO
ViRobotTrojan.Win32.Blocker.Gen.B
ZoneAlarmHEUR:Worm.Win32.Agent.gen
MicrosoftTrojan:Win32/Dinwod!pz
VaristW32/Pykspa.A.gen!Eldorado
AhnLab-V3Trojan/Win32.Zepfod.R4378
Acronissuspicious
VBA32Worm.Yah
ALYacTrojan.AgentWDCR.JMO
TACHYONWorm/W32.SkypeBot.2195456
Cylanceunsafe
PandaW32/SpySkype.E
TrendMicro-HouseCallTROJ_AGENT_006376.TOMB
RisingWorm.Autorun!1.BC87 (CLASSIC)
IkarusTrojan.Agent
MaxSecureBackdoor.Zepfod.A
FortinetW32/AutoRun.AGENT.AUA!tr
AVGWin32:Renos-KY [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Dinwod!pz?

Trojan:Win32/Dinwod!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment