Trojan

Trojan:Win32/Dishigy.B (file analysis)

Malware Removal

The Trojan:Win32/Dishigy.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Dishigy.B virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

jfasfasfasfasf.com

How to determine Trojan:Win32/Dishigy.B?


File Info:

crc32: EEC8206B
md5: 35acbb01d93e7032b912502f6ce2b653
name: 35ACBB01D93E7032B912502F6CE2B653.mlw
sha1: 3226f8e6a28a0028f881fac24c037321051b5a5c
sha256: 7a5c8954a6dd9159517eb01405965556b1c93d8ed04b44d13ed7bc4ed83f8c20
sha512: f0be25e63d02b88ece6b8c699cea2d355e228683c6525be6887c700ea9eaf59e157c6910831854cbe40780f8e2baeb61a9497ce52f9464af025e4fd52cfe7876
ssdeep: 6144:TImmqavduDq4CZED69Nx4eKEL/MTl8ghqqMxc:GqquDqZyDSnKE7MJ3qqMi
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9 Msfkafj Srggwlfnyy 1999-2006
InternalName: Msfkafj
FileVersion: 89, 74, 68, 66
CompanyName: Msfkafj Srggwlfnyy
ProductName: Msfkafj
ProductVersion: 89, 74, 68, 66
FileDescription: Msfkafj Qstwwyanvt Onudfdo
OriginalFilename: Ffmojnu.exe
Translation: 0x0409 0x04b0

Trojan:Win32/Dishigy.B also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055dd191 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebBackDoor.DirtJump.1
CynetMalicious (score: 99)
ALYacGen:Variant.Kazy.24669
CylanceUnsafe
ZillyaTrojan.Jorik.Win32.6162
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win32/Dishigy.083522fb
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.1d93e7
CyrenW32/Zbot.DA.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.OIY
APEXMalicious
AvastFileRepMetagen [Malware]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Kazy.24669
NANO-AntivirusTrojan.Win32.Dwn.dbzek
MicroWorld-eScanGen:Variant.Kazy.24669
TencentWin32.Trojan.Generic.Lkoa
Ad-AwareGen:Variant.Kazy.24669
SophosMal/Generic-R + Mal/Zbot-CX
ComodoMalware@#3uf3xvga7s0sd
BitDefenderThetaGen:NN.ZexaF.34266.pmKfaiCJ7qdi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
FireEyeGeneric.mg.35acbb01d93e7032
EmsisoftGen:Variant.Kazy.24669 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Jorik.jdk
WebrootW32.Trojan.Gen
AviraTR/Crypt.ULPM.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.37D7E9
KingsoftWin32.Troj.Jorik.bh.(kcloud)
MicrosoftTrojan:Win32/Dishigy.B
ArcabitTrojan.Kazy.D605D
GDataGen:Variant.Kazy.24669
McAfeeArtemis!35ACBB01D93E
MAXmalware (ai score=100)
PandaGeneric Malware
YandexTrojan.Kryptik!b9X5SYmGR+4
IkarusBackdoor.Win32.Skill
MaxSecureTrojan.Malware.2328355.susgen
FortinetW32/Jorik_Skill.BH!tr
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml

How to remove Trojan:Win32/Dishigy.B?

Trojan:Win32/Dishigy.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment