Trojan

How to remove “Trojan:Win32/Gatak.DU!dha”?

Malware Removal

The Trojan:Win32/Gatak.DU!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Gatak.DU!dha virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Trojan:Win32/Gatak.DU!dha?


File Info:

name: AB7160E7F0E722C7A576.mlw
path: /opt/CAPEv2/storage/binaries/e6ecbc0e4124318591cf6f67d69b039baca2b90eb0ff3889af882bceb0f5d278
crc32: E1A95AED
md5: ab7160e7f0e722c7a576a2e92c3a69d9
sha1: 58fad568219318bc8b5b4f22433ec2fbe24b61f4
sha256: e6ecbc0e4124318591cf6f67d69b039baca2b90eb0ff3889af882bceb0f5d278
sha512: bd9702004d733465712b64b0339f3cc1803cf5d4df6c16ac046385ec4d3e2ac1dff5847f066d3f9ed2cf221128ccbd4cd77b898fd9efb61ca2da0575e75dba9e
ssdeep: 6144:BcveRe7Jk0frcWQDLX/D+9J92rMiowRUtUAItZbRDJG2hbuzc7i52ARDv:BcveRe7JnfIWQDLX/y9J94MsjZJGW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B654CF7D30E451F0EDB2D534195AC376FE29B62326A29042C734E954B9382BE1D236FE
sha3_384: 97337ab26e09cf51c0f83312d71819103a64682332276f25731ae71a66fe49f4798858de0aa1758182b8b316874adb21
ep_bytes: 558bec6aff68401142006844d7410064
timestamp: 2007-08-06 13:43:36

Version Info:

0: [No Data]

Trojan:Win32/Gatak.DU!dha also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.4030
FireEyeGeneric.mg.ab7160e7f0e722c7
McAfeeArtemis!AB7160E7F0E7
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.898975
SangforTrojan.Win32.Zbot.54222
K7AntiVirusTrojan ( 0055dd191 )
AlibabaTrojan:Win32/Kryptik.f947ad48
K7GWTrojan ( 0055dd191 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.BIJM
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.4030
NANO-AntivirusTrojan.Win32.ZBot.efbipx
AvastWin32:MalOb-JL [Cryp]
TencentWin32.Trojan.Generic.Lohl
Ad-AwareGen:Variant.Symmi.4030
EmsisoftGen:Variant.Symmi.4030 (B)
VIPRETrojan-Downloader.Tibs.gen (v)
SophosML/PE-A + Mal/FakeAV-FS
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Symmi.4030
JiangminTrojan/Generic.xlyj
AviraTR/Spy.Zbot.54222
ArcabitTrojan.Symmi.DFBE
MicrosoftTrojan:Win32/Gatak.DU!dha
CynetMalicious (score: 99)
BitDefenderThetaAI:Packer.D82912C91F
ALYacGen:Variant.Symmi.4030
MAXmalware (ai score=100)
VBA32Trojan.Wacatac
MalwarebytesGeneric.Malware/Suspicious
YandexTrojan.Agent!d9gZBXfJ2iI
IkarusVirus.Win32.Cryptor
eGambitGeneric.Malware
FortinetW32/Agent.XOT!tr
AVGWin32:MalOb-JL [Cryp]

How to remove Trojan:Win32/Gatak.DU!dha?

Trojan:Win32/Gatak.DU!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment