Trojan

AIT:Trojan.Agent.DTNO removal

Malware Removal

The AIT:Trojan.Agent.DTNO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Agent.DTNO virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Starts servers listening on 127.0.0.1:0
  • Executed a process and injected code into it, probably while unpacking
  • Anomalous binary characteristics

How to determine AIT:Trojan.Agent.DTNO?


File Info:

crc32: 93848F5C
md5: 2867b3c9e16f2be5bbcb595d8cf90676
name: 2867B3C9E16F2BE5BBCB595D8CF90676.mlw
sha1: 4a0c9a455cc240ac71c125be97019923965f1ad5
sha256: 1f7bf2479afee06220c111e8f642334cd4659ca96a2c3a523401e5362ac59b84
sha512: c0f6e77fd35e5e9aa4a88664302d7c2f29b72cf8f1422b6cda5ad7d4d9e3e8109802c02b3beeb5e7e7205e67f5f78b3ca7dcc187a6f72e2bf8e0ff80e390164e
ssdeep: 24576:Ke7DNyWsNBFI2vOk84Y2yK4mHaKvpaEPKs4wux5zryj2SFqJHXK1g5:vNozPY2ytYaKWV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

AIT:Trojan.Agent.DTNO also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanAIT:Trojan.Agent.DTNO
FireEyeGeneric.mg.2867b3c9e16f2be5
CAT-QuickHealTrojan.AutoIt.Wacatac.R
Qihoo-360HEUR/QVM10.1.4CC2.Malware.Gen
ALYacAIT:Trojan.Agent.DTNO
CylanceUnsafe
SangforMalware
BitDefenderAIT:Trojan.Agent.DTNO
Cybereasonmalicious.9e16f2
TrendMicroTrojan.AutoIt.CRYPTINJECT.SMA
CyrenW32/AutoIt.IJ.gen!Eldorado
SymantecPacked.Generic.548
APEXMalicious
ClamAVWin.Malware.Dtno-6936527-0
KasperskyTrojan.Script.Obit.gen
NANO-AntivirusTrojan.Script.Packed2.fpbxec
RisingTrojan.Injector/Autoit!1.BB8F (CLASSIC)
Ad-AwareAIT:Trojan.Agent.DTNO
EmsisoftAIT:Trojan.Agent.DTNO (B)
F-SecureDropper.DR/AutoIt.Gen8
DrWebTrojan.AutoIt.381
InvinceaML/PE-A + Mal/AuItInj-A
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.vh
SophosMal/AuItInj-A
IkarusTrojan.Autoit
AviraDR/AutoIt.Gen8
MAXmalware (ai score=82)
Antiy-AVLGrayWare/Autoit.ShellCode.a
MicrosoftVirTool:Win32/AutInject.CZ!bit
ArcabitAIT:Trojan.Agent.DTNO
ZoneAlarmTrojan.Script.Obit.gen
GDataAIT:Trojan.Agent.DTNO (2x)
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/AutoInj.Exp
McAfeeArtemis!2867B3C9E16F
MalwarebytesSpyware.HawkEyeKeyLogger
ESET-NOD32a variant of Win32/Packed.AutoIt.PC
TrendMicro-HouseCallTrojan.AutoIt.CRYPTINJECT.SMA
YandexTrojan.AvsArher.bS9LKk
eGambitUnsafe.AI_Score_100%
FortinetAutoIt/Injector.DWD!tr
BitDefenderThetaAI:Packer.324F74D815
AVGAutoIt:Injector-JF [Trj]
AvastAutoIt:Injector-JF [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove AIT:Trojan.Agent.DTNO?

AIT:Trojan.Agent.DTNO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment