Trojan

Trojan.Agent.DATO (file analysis)

Malware Removal

The Trojan.Agent.DATO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.DATO virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Agent.DATO?


File Info:

crc32: CBCFBCE5
md5: c9290fb6596762852da17b1c4ab3ec8e
name: C9290FB6596762852DA17B1C4AB3EC8E.mlw
sha1: 529760f7cb7555e03dc49192786733fcfd7dd7f0
sha256: 217f8f53fb7602ab45d245945ebcabdaa50457c62f5fa5f61dcf6ee5fcac39c2
sha512: 4b2859d3ef900574e7ede1edad0ec86670264d0cd4afac7dd503a19d7f61ca7b6834785bc26c4dcacd08e9a20c9409cd5e91ac50e925d287bbf1a2fd0d1827fe
ssdeep: 49152:bdHLxhASONNXGg7XO9Ti3FYZ1WBfR10yV+gqUD01iN8CPchlRSzxaa60Ee:bxDAZd7XQTKmk5100qMQo1khlRSz00Ee
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9Cceyleteled inlociidnu
InternalName: TAHOMIANLEARRA.EXE
FileVersion: 4.9.1.2
CompanyName: xa9Cceyleteled inlociidnu
ProductName: TAHOMIANLEARRA
ProductVersion: 4.9.1.2
OriginalFilename: tahomianlearra.exe
Translation: 0x0409 0x04e4

Trojan.Agent.DATO also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005375761 )
Elasticmalicious (high confidence)
DrWebTrojan.Zadved.936
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Occamy.A1
ALYacTrojan.Agent.DATO
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3085633
SangforTrojan.Win32.Save.a
K7GWTrojan ( 005375761 )
Cybereasonmalicious.659676
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GIDA
APEXMalicious
AvastWin32:Dropper-gen [Drp]
Kasperskynot-a-virus:HEUR:AdWare.Win32.StartSurf.gen
BitDefenderTrojan.Agent.DATO
NANO-AntivirusTrojan.Win32.Snojan.fercsw
MicroWorld-eScanTrojan.Agent.DATO
Ad-AwareTrojan.Agent.DATO
SophosMal/Generic-S
ComodoTrojWare.Win32.Trojan.XPack.~gen1@1rwlif
BitDefenderThetaGen:NN.ZexaF.34294.Pt0@ainEr1ii
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPacked-FFF!C9290FB65967
FireEyeGeneric.mg.c9290fb659676285
EmsisoftTrojan.Agent.DATO (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.StartSurf.dbxj
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.26C721B
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.Agent.DATO
AhnLab-V3Malware/Win32.Generic.C2592186
Acronissuspicious
McAfeePacked-FFF!C9290FB65967
MAXmalware (ai score=99)
VBA32BScope.Downloader.Snojan
MalwarebytesMalware.AI.4089991333
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.B33C (CLASSIC)
YandexPUA.Downloader!9XV9P8AU2ho
IkarusPUA.Win32.Dlhelper
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.FSMR!tr
AVGWin32:Dropper-gen [Drp]
Paloaltogeneric.ml

How to remove Trojan.Agent.DATO?

Trojan.Agent.DATO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment