Trojan

Trojan.Agent.DAJA removal tips

Malware Removal

The Trojan.Agent.DAJA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.DAJA virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • CAPE detected the Fareit malware family
  • Harvests cookies for information gathering
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

How to determine Trojan.Agent.DAJA?


File Info:

name: F62DF40B6ACF637ED545.mlw
path: /opt/CAPEv2/storage/binaries/e0c6511048675f6a2258ca308725844bd25057725f40d260b642f52a3b0a0357
crc32: 9CAEB16D
md5: f62df40b6acf637ed54515623b9d7af7
sha1: 65d6edddb26625d2af520743b94934ee07e2e694
sha256: e0c6511048675f6a2258ca308725844bd25057725f40d260b642f52a3b0a0357
sha512: fad620311871f1f5bc5d05eafc67aaf54189922596bd66ecc2e70817ffbde4bdd3e9713af2f8dcbfceb9665d9ff3e401c10bdf688a69d78e72a8ecdd7bb7e034
ssdeep: 1536:uM8YPYAQqTzTm19EUEtKFhwlA808G/pB2Ol9CATvoEKhkzZMvVsaGJmVTcYA6jip:n8rACkDlASOqJEKKMtsjmiQjvZIMbBM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18FF32A03B481E0F1C0A12A71ABC15668EFFD7D64783E8DDBEF4C4D46E9A1E876792052
sha3_384: a9b692f0b2fb66a74061dc966cb20d2ce32411fe099a7a9e91a5e20081fa2ea8576f53d8dbba610fdfe7862ff092d3f7
ep_bytes: 558bec5d68f9014100f87201c3ffe854
timestamp: 2016-10-04 02:53:32

Version Info:

0: [No Data]

Trojan.Agent.DAJA also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.1932
MicroWorld-eScanTrojan.Agent.DAJA
FireEyeGeneric.mg.f62df40b6acf637e
CAT-QuickHealPWS.Fareit.E3
ALYacTrojan.Agent.DAJA
CylanceUnsafe
ZillyaTrojan.Tepfer.Win32.87711
SangforTrojan.Win32.Save.a
K7AntiVirusPassword-Stealer ( 0040f4f51 )
K7GWPassword-Stealer ( 0040f4f51 )
Cybereasonmalicious.b6acf6
ArcabitTrojan.Agent.DAJA
BitDefenderThetaGen:NN.ZexaF.34212.kmZ@ame0Rxi
VirITTrojan.Win32.Generic.BHAO
CyrenW32/A-f0951580!Eldorado
SymantecInfostealer!im
ESET-NOD32a variant of Win32/PSW.Fareit.D
TrendMicro-HouseCallBKDR_PONY.SM
ClamAVWin.Trojan.PonyStealer-9831667-0
KasperskyTrojan-PSW.Win32.Tepfer.gen
BitDefenderTrojan.Agent.DAJA
NANO-AntivirusTrojan.Win32.Siggen.evgeyh
AvastSf:Crypt-AS [Trj]
TencentTrojan.Win32.Tepfer.a
Ad-AwareTrojan.Agent.DAJA
ComodoTrojWare.Win32.PWS.Fareit.GS@5t8zib
VIPRETrojan.Win32.Fareit.gi (v)
TrendMicroBKDR_PONY.SM
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.ch
EmsisoftTrojan.Agent.DAJA (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/PSW.Tepfer.cadv
AviraTR/PSW.Fareit.iloen
MAXmalware (ai score=80)
Antiy-AVLTrojan[PSW]/Win32.Tepfer
MicrosoftPWS:Win32/Fareit
ViRobotBackdoor.Win32.Pony.Gen.A
GDataWin32.Trojan-Stealer.Zbot.AB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Ponik.R49463
Acronissuspicious
VBA32BScope.Malware-Cryptor.Ponik
MalwarebytesSpyware.Pony
APEXMalicious
RisingStealer.Fareit!1.B777 (RDMK:cmRtazotGngPDZX4h3vLASF8faGk)
YandexTrojan.GenAsa!qzB/BOkUj5k
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.14B!tr
AVGSf:Crypt-AS [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Agent.DAJA?

Trojan.Agent.DAJA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment