Trojan

AIT:Trojan.Agent.DPOI removal guide

Malware Removal

The AIT:Trojan.Agent.DPOI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Agent.DPOI virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine AIT:Trojan.Agent.DPOI?


File Info:

name: 5085657E20E985C00E39.mlw
path: /opt/CAPEv2/storage/binaries/78f4eaba391d090b588ba610ad3e49a9dd1947127b002bfc373d65d665d6bcde
crc32: 22C99A22
md5: 5085657e20e985c00e3963502817f72e
sha1: a797ee7a5d6def4308fb94665007099aed9ca1a9
sha256: 78f4eaba391d090b588ba610ad3e49a9dd1947127b002bfc373d65d665d6bcde
sha512: c0f7b52d5edfa076fe55769054c54bdf77df10e3987a684ff75df222ec7bb71dab0c0a9d9417a8af6b9b595cdea6dbe348b5fc0c71615b31ceca421f6bb5dd67
ssdeep: 24576:N2O/Gl+n0FwW2EN7SBLlKk1KRshB695D0MwmxhKbH3rUO46Gvt:nrWrwEAKRsh4LBwmxUT3iHt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1044523123ED814B6E9A295301F7A3B86FCB8EE38617AF50FD756001E79B6242551B333
sha3_384: ae3574ddca92b9f0332529e3a668019d3464ffdc12296ac2938a93f941b332a0945229db96730b7efa1b5a3a6c799030
ep_bytes: e8e3feffff33c050505050e89f300000
timestamp: 2012-06-09 13:19:49

Version Info:

0: [No Data]

AIT:Trojan.Agent.DPOI also known as:

LionicTrojan.Win32.Mycop.4!c
DrWebTrojan.PWS.Stealer.19347
MicroWorld-eScanAIT:Trojan.Agent.DPOI
ClamAVWin.Malware.Generic-7433444-0
FireEyeGeneric.mg.5085657e20e985c0
McAfeeArtemis!5085657E20E9
MalwarebytesGeneric.Trojan.Injector.DDS
SangforTrojan.Win32.Injector.Vl3h
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/runner.ali1000123
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderThetaAI:Packer.C53E487015
VirITTrojan.Win32.Stealer.BCQD
CyrenW32/Downloader.JUQB-3573
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Injector.Autoit.DTG
ZonerProbably Heur.RARAutorun
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderAIT:Trojan.Agent.DPOI
NANO-AntivirusTrojan.Win32.Mycop.fmwpjj
AvastWin32:Trojan-gen
TencentWin32.Trojan-Dropper.Generic.Qqil
EmsisoftAIT:Trojan.Agent.DPOI (B)
VIPREAIT:Trojan.Agent.DPOI
TrendMicroTrojan.AutoIt.NANOCORE.SM
McAfee-GW-EditionTrojan-aitinject.ah
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
GDataAIT:Trojan.Agent.DPOI
MAXmalware (ai score=100)
XcitiumMalware@#3ikhojgllkd0r
ArcabitAIT:Trojan.Agent.DPOI
ZoneAlarmHEUR:Trojan.Win32.Autoit.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Malware/Gen.Generic.C3010289
ALYacAIT:Trojan.Agent.DPOI
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTrojan.AutoIt.NANOCORE.SM
RisingTrojan.Injector!8.C4 (TOPIS:E0:z2B8gMlD3vE)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.10984924.susgen
FortinetAutoIt/Injector.DWH!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.e20e98
DeepInstinctMALICIOUS

How to remove AIT:Trojan.Agent.DPOI?

AIT:Trojan.Agent.DPOI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment