Trojan

Trojan.Agent.DAHM (file analysis)

Malware Removal

The Trojan.Agent.DAHM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.DAHM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Agent.DAHM?


File Info:

name: BD2839B425305A3A5297.mlw
path: /opt/CAPEv2/storage/binaries/1efa1f285b8b4aca7e3719b535abd9798e3e0fb3a326fc66111f256ad2e1e113
crc32: ED369FD5
md5: bd2839b425305a3a5297d69998f7e3aa
sha1: 67c9ecca4df40557a191d55fe6eb72602c1a5100
sha256: 1efa1f285b8b4aca7e3719b535abd9798e3e0fb3a326fc66111f256ad2e1e113
sha512: a52e2be694c5f4710066b260c0b43670b9075986902d22debe864eab3e83e8bfac25849f81dcf471acf894221d98db1cbc5e772faa220ecd7bd459899037c987
ssdeep: 12288:wyBA2hNE4U1UaoUWcdd6Ro8AP3h/LtVsSrwoeK:wyBDqloRWY7c/DDwoe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T193A5120B32919832D1226D355828C6D8413F7E650FA85EFBB7542B3E7E354C0A939F7A
sha3_384: 8be75611affb7388d2ba3be750bd0e2e632298f520e5d2ce0cef74647b93bc9f0522f38126aba144226404072cba9293
ep_bytes: e890030000e98efeffff558bec6a00ff
timestamp: 2018-06-19 09:30:08

Version Info:

0: [No Data]

Trojan.Agent.DAHM also known as:

LionicAdware.Win32.Generic.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.DAHM
FireEyeGeneric.mg.bd2839b425305a3a
CAT-QuickHealSoftwBndlr.Prepscram.MUE.ZZ6
SkyhighPUP-XFX-AW
McAfeePUP-XFX-AW
MalwarebytesCrypt.Trojan.Malicious.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005361661 )
AlibabaAdWare:Win32/StartSurf.0e1809a7
K7GWTrojan ( 0052ceff1 )
Cybereasonmalicious.a4df40
ArcabitTrojan.Agent.DAHM
BitDefenderThetaGen:NN.ZexaF.36744.kAW@a0XKmbji
SymantecAdware.IstartSurf
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.GFGF
APEXMalicious
CynetMalicious (score: 99)
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderTrojan.Agent.DAHM
NANO-AntivirusRiskware.Win32.Kryptik.fegmae
AvastWin32:StartSurf-C [Adw]
TencentMalware.Win32.Gencirc.10b21035
EmsisoftTrojan.Agent.DAHM (B)
F-SecureHeuristic.HEUR/AGEN.1363305
VIPRETrojan.Agent.DAHM
Trapminemalicious.high.ml.score
SophosMal/Isda-D
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.gen
GoogleDetected
AviraHEUR/AGEN.1363305
Antiy-AVLGrayWare[AdWare]/Win32.AGeneric
XcitiumApplication.Win32.IStartSurf.PS@8c4m91
MicrosoftSoftwareBundler:Win32/Prepscram
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Generic
GDataTrojan.Agent.DAHM
VaristW32/Trojan.CBI.gen!Eldorado
AhnLab-V3PUP/Win32.Bundler.R230510
VBA32BScope.Adware.Prepscram
ALYacTrojan.Agent.DAHM
MAXmalware (ai score=99)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!8.8 (TFE:1:lZIpVEjq6KH)
YandexTrojan.GenAsa!HulyS+ThGaY
IkarusTrojan.Crypt
FortinetW32/Kryptik.FMTV!tr
AVGWin32:StartSurf-C [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan.Agent.DAHM?

Trojan.Agent.DAHM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment