Malware

Should I remove “Dropped:Application.Agent.DGM”?

Malware Removal

The Dropped:Application.Agent.DGM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Application.Agent.DGM virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Hebrew
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Dropped:Application.Agent.DGM?


File Info:

name: F106310F2074E18B66EB.mlw
path: /opt/CAPEv2/storage/binaries/d28141d2ab6e430a8d873e7c1f2ea0d7c0332b1fb62009fb5cd653ae627d6c2b
crc32: F7F4EBDA
md5: f106310f2074e18b66eb708259def34d
sha1: a9e9fab65a86c6ee8e412a0df4112315ff8fe8cd
sha256: d28141d2ab6e430a8d873e7c1f2ea0d7c0332b1fb62009fb5cd653ae627d6c2b
sha512: c20cf9b0f47824a35baa01e03fa1503e316b77424cd46b33cb34819fc9c360ac814f83abf3467b6cadc95aa25d868ba2186bd9d8cb4450d184333fa3720635d2
ssdeep: 24576:gpWmAFV/MOsB8lsMcfWt3t/vTDL+KGF8rjdB1ilv:J/MOsBmsMcfWtVv7W8flAv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A605023AF181C47BC0715A3C8D86C2E5A529BA202D2C186F75E90F5E5E3F1E3566D2CB
sha3_384: e4509a4bd12e8c3114aa6361e6e0309fdb23065b53b88678a9cffc4057d129ebd2dcf8676746cf5ca5fad256ee9cf005
ep_bytes: 558bec83c4f0b8cc664200e854f0fdff
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Pantaray Research Ltd.
FileDescription: Setup SFX Kernel
FileVersion: 10.0.0.1
InternalName: Setup SFX Kernel
LegalCopyright: Copyright (C) 2002-2010, Pantaray Research Ltd.
LegalTrademarks:
OriginalFilename: Stub.exe
ProductName:
ProductVersion: 10.0.0.0
Comments:
Translation: 0x0409 0x04e4

Dropped:Application.Agent.DGM also known as:

MicroWorld-eScanDropped:Application.Agent.DGM
FireEyeDropped:Application.Agent.DGM
McAfeeArtemis!F106310F2074
CylanceUnsafe
ZillyaAdware.Installpedia.Win32.1
SangforAdware.Win32.InstallPedia.p
AlibabaAdWare:Win32/InstallPedia.d3079a01
Cybereasonmalicious.f2074e
SymantecPUA.Gen.2
ESET-NOD32multiple detections
TrendMicro-HouseCallTROJ_GEN.R002H07IG21
Paloaltogeneric.ml
Kasperskynot-a-virus:AdWare.Win32.InstallPedia.p
BitDefenderDropped:Application.Agent.DGM
NANO-AntivirusRiskware.Win32.InstallPedia.fbbxpy
SUPERAntiSpywarePUP.InstallPedia/Variant
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.10bb0d3e
Ad-AwareDropped:Application.Agent.DGM
SophosGeneric PUA KJ (PUA)
ComodoMalware@#9hpgg7sfhboq
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.PUP.cc
EmsisoftDropped:Application.Agent.DGM (B)
IkarusWin32.Malware
JiangminAdWare.InstallPedia.d
WebrootW32.Malware.Gen
MicrosoftProgram:Win32/Wacapew.C!ml
ViRobotAdware.Installpedia.823155
GDataDropped:Application.Agent.DGM
VBA32AdWare.InstallPedia
ALYacDropped:Application.Agent.DGM
MAXmalware (ai score=70)
APEXMalicious
YandexPUA.InstallPedia!to81k3lLZ/o
AVGWin32:Adware-gen [Adw]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Dropped:Application.Agent.DGM?

Dropped:Application.Agent.DGM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment