Trojan

What is “Trojan:Win32/Dizemp.GKL!MTB”?

Malware Removal

The Trojan:Win32/Dizemp.GKL!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Dizemp.GKL!MTB virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Dizemp.GKL!MTB?


File Info:

name: FF97A8A053484852D070.mlw
path: /opt/CAPEv2/storage/binaries/07d950614c1129d88e54ce3798066007f6a28bcb4ee71bdf23612203e2116fdc
crc32: 6C6E7644
md5: ff97a8a053484852d0706d071374f30c
sha1: 64967913e891a6078cf11881fef675bad6229450
sha256: 07d950614c1129d88e54ce3798066007f6a28bcb4ee71bdf23612203e2116fdc
sha512: afa4e1676e600d3924e3d5070fe98574882a9fe8f058bd99614b0093a2d00755ad168a25648e40fbd7da22b886060f314563e378481048c43a212bd28511e9a6
ssdeep: 384:McIjmNqOeSCid95rYARBWHH2MvEcoqR+:MYq1MCead8
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T166624B0AB26844B5C3A4013838596723D57C6FB424F461D36BE78D4CAEAD2A7BDA4D03
sha3_384: de0254d9c846185e572348a11ae4c95c0e2f16d4ce77f022c5beb2c3ed3ef9e3eb4537350105d674086720815a62bedb
ep_bytes: 558bec83c4e056528b5510920bc07407
timestamp: 2019-12-04 11:22:42

Version Info:

0: [No Data]

Trojan:Win32/Dizemp.GKL!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cerbu.63936
SkyhighBehavesLike.Win32.Worm.lm
McAfeeArtemis!FF97A8A05348
Cylanceunsafe
ZillyaTrojan.Agent.Win32.1201158
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/ATRAPS.9159dbcb
K7GWTrojan ( 00561c1a1 )
K7AntiVirusTrojan ( 00561c1a1 )
ArcabitTrojan.Cerbu.DF9C0
BitDefenderThetaGen:NN.ZedlaF.36680.aq5@a4dEiTd
VirITTrojan.Win32.Small.TM
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanProxy.Agent.ODP
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Cerbu.63936
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:DropperX-gen [Drp]
TencentMalware.Win32.Gencirc.10b2ea02
EmsisoftGen:Variant.Cerbu.63936 (B)
F-SecureTrojan.TR/ATRAPS.Gen4
DrWebTrojan.Proxy2.1677
VIPREGen:Variant.Cerbu.63936
TrendMicroTROJ_GEN.R002C0DAH24
SophosMal/Generic-S
IkarusTrojan-Proxy.Agent
JiangminTrojanDownloader.Small.ccmm
VaristW32/ProxyAgent.J.gen!Eldorado
AviraTR/ATRAPS.Gen4
Antiy-AVLGrayWare/Win32.TrojanProxy.a
Kingsoftmalware.kb.a.996
MicrosoftTrojan:Win32/Dizemp.GKL!MTB
ViRobotTrojan.Win.Z.Agent.14848.KVV
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Cerbu.63936
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R298422
ALYacGen:Variant.Cerbu.63936
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DAH24
RisingDownloader.Small!8.B41 (TFE:3:uRLrtthHxvK)
YandexTrojan.GenAsa!9AXumfnBX3o
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.34721.susgen
FortinetW32/Agent.ODD!tr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Dizemp.GKL!MTB?

Trojan:Win32/Dizemp.GKL!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment