Trojan

UDS:Trojan-Dropper.Win32.Dapato information

Malware Removal

The UDS:Trojan-Dropper.Win32.Dapato is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-Dropper.Win32.Dapato virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (7 unique times)
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • A scripting utility was executed
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to identify installed AV products by installation directory
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

www.duplicatefilesfixer.com
apps.identrust.com
r3.o.lencr.org
activate123.com
crl.identrust.com

How to determine UDS:Trojan-Dropper.Win32.Dapato?


File Info:

crc32: DC4FBB5A
md5: a6000dc2d7e32df066079f4a2ff91e35
name: A6000DC2D7E32DF066079F4A2FF91E35.mlw
sha1: 7fd9fabb206082c75a0719cadab7287097234aa6
sha256: 1b7d7515f98891cf08164a7469bb9c9f3133e7834cfe99d55094594ca330e982
sha512: b0f5cab846c5615c9eb47ab08d9076c0ba1316ff3492e64a476eab0af2fc1a7dea60e040060ed28add508eba30937e8a690f5376d5209df970b77582637e1422
ssdeep: 98304:mAI+qSlex5u6+tLvHREJTSeEehw1F+cgyThOMYYYjyDAbsr9CjdiECMFKHq3/Iub:VtqieGeJmeDolVvwjoY0qMHLjixF7gzW
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Systweak Software
FileDescription: Duplicate Files Fixer 1.2.0.10608 Installation
FileVersion: 1.2.0.10608
Comments:
CompanyName: Systweak Software
Translation: 0x0409 0x04e4

UDS:Trojan-Dropper.Win32.Dapato also known as:

K7AntiVirusTrojan ( 00536ee01 )
Elasticmalicious (high confidence)
DrWebProgram.Unwanted.4458
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37115940
SangforTrojan.Win32.Dapato.ky
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/runner.ali1000123
K7GWTrojan ( 00536ee01 )
Cybereasonmalicious.b20608
CyrenW32/MSIL_Kryptik.DLQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:RATX-gen [Trj]
KasperskyUDS:Trojan-Dropper.Win32.Dapato
BitDefenderTrojan.GenericKD.37115940
NANO-AntivirusTrojan.Win32.Quasar.iwmkjw
MicroWorld-eScanTrojan.GenericKD.37115940
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.wc
FireEyeGeneric.mg.a6000dc2d7e32df0
EmsisoftTrojan.GenericKD.37115940 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Kryptik.lnljc
MicrosoftRansom:Win32/Crypmod
ArcabitTrojan.Generic.D2365824
AegisLabTrojan.VBS.Alien.4!c
GDataMSIL.Backdoor.ASyncRAT.MUOBDC
McAfeeArtemis!A6000DC2D7E3
MAXmalware (ai score=82)
VBA32TScope.Trojan.MSIL
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H07FG21
IkarusTrojan.Win32.Cab
eGambitUnsafe.AI_Score_100%
FortinetRiskware/Quasar
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml

How to remove UDS:Trojan-Dropper.Win32.Dapato?

UDS:Trojan-Dropper.Win32.Dapato removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment