Trojan

Trojan:Win32/Gatak.BK!dha removal instruction

Malware Removal

The Trojan:Win32/Gatak.BK!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Gatak.BK!dha virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan:Win32/Gatak.BK!dha?


File Info:

name: F9524AFF9D1285F0382F.mlw
path: /opt/CAPEv2/storage/binaries/d7d7cadb0778375fa9bb959ee80fa55d6f128593ac255875803bc8f932c1df03
crc32: A68F898A
md5: f9524aff9d1285f0382f88fd6b639c16
sha1: 68d70f471410e26cd9ac3b5104e02c26ffbd4a28
sha256: d7d7cadb0778375fa9bb959ee80fa55d6f128593ac255875803bc8f932c1df03
sha512: 35bbebdb7688b34a5ac03352ec0c6bd42effd6baa0b01aea313185dd5dfe9cfff511858241dc5671aeec0a1db60c9c2e10b741595309f33e00c111fbb0ae6ce0
ssdeep: 3072:WAf/d1sXeOT5cU2xluAsf6n9c9tGTOuPeJWqjXRmMt4xmFVdo4InkfjR:tfF1lOlMnc6nafqPeB19rDjR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11CF31237407E8EABFA1D2BF845512918B2D113BCA24DF02F95A627254D8BDB075F8D38
sha3_384: 0d544bbd31b1075af999f82fb3f87bdd64aaba345d323115a2e134e6806098330effe56d44f4b3fb0c0ebe55d8a01159
ep_bytes: 60be15e041008dbeeb2ffeff57eb0b90
timestamp: 2008-04-07 19:31:52

Version Info:

0: [No Data]

Trojan:Win32/Gatak.BK!dha also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zbot.54
FireEyeGeneric.mg.f9524aff9d1285f0
McAfeeRDN/Generic.hbg
VIPRETrojan.Win32.Generic!BT
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Gatak.3d1adc89
K7GWTrojan ( 0055dd191 )
K7AntiVirusTrojan ( 0055dd191 )
BitDefenderThetaAI:Packer.629E17081E
SymantecTrojan.Gatak!gen
ESET-NOD32a variant of Win32/Kryptik.BIJM
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zbot.54
NANO-AntivirusTrojan.Win32.ZBot.ecgawe
AvastWin32:MalOb-JL [Cryp]
TencentWin32.Trojan.Spy.Edne
Ad-AwareGen:Variant.Zbot.54
SophosMal/Generic-R + Mal/FakeAV-FS
ComodoMalware@#3bqu4mo6b32v8
ZillyaTrojan.Kryptik.Win32.2847483
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
EmsisoftGen:Variant.Zbot.54 (B)
IkarusVirus.Win32.Cryptor
JiangminTrojan/Generic.xahc
eGambitGeneric.Malware
AviraTR/Spy.Zbot.54222
MicrosoftTrojan:Win32/Gatak.BK!dha
GDataGen:Variant.Zbot.54
SentinelOneStatic AI – Suspicious PE
AhnLab-V3Trojan/Win.Gatak.R455257
VBA32Trojan.Gatak
ALYacGen:Variant.Zbot.54
APEXMalicious
YandexTrojan.GenAsa!jqZ1x4GLMT8
MAXmalware (ai score=100)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.XOT!tr
WebrootW32.Backdoor.Gen
AVGWin32:MalOb-JL [Cryp]
PandaTrj/Genetic.gen

How to remove Trojan:Win32/Gatak.BK!dha?

Trojan:Win32/Gatak.BK!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment