Trojan

Trojan.Agent.DATX malicious file

Malware Removal

The Trojan.Agent.DATX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.DATX virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Agent.DATX?


File Info:

name: B44E3D7A23DF5B4188DD.mlw
path: /opt/CAPEv2/storage/binaries/4230a4aff264a1b0c4dcf7f22ef5f43b0e7b70a2ca603587807fd2a4a1be8fb9
crc32: 8BAA2004
md5: b44e3d7a23df5b4188dde5e2d823ab60
sha1: 1241ee7725cc7f9631e0aa10d6f0249ba99e9fb7
sha256: 4230a4aff264a1b0c4dcf7f22ef5f43b0e7b70a2ca603587807fd2a4a1be8fb9
sha512: ea19ea5cdd3a5546665aeb0039af602a2e80cf95e17e629803ce28de440ea880a560f58f06507a10bb3735dabc789f6273d64385ca8895dd70f3f263dcfc1fe0
ssdeep: 24576:CRrKzsHLF579q0BBuY5q3gP4IDbhfZeFQSnzAZN8FOGKTLHRgggg0gggggggzgV5:I2c79qO7DDJZeqO+m12TB/2TB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C7C5E003732CB402C4BA88BB3E785EBBAD557D06511BA485FF535BD6D29AF742E00923
sha3_384: 59692fc3bb30b6de7b8b2b415f97661177e3bdfa0f8d94f606b73c976c175532594b53b5ef271b7a776e0cfac69420fa
ep_bytes: e8ad030000e98efeffff558bec6a00ff
timestamp: 2018-06-29 13:47:49

Version Info:

0: [No Data]

Trojan.Agent.DATX also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.Prepscram.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.DATX
FireEyeGeneric.mg.b44e3d7a23df5b41
CAT-QuickHealPUA.PrepscramRI.S18994084
SkyhighBehavesLike.Win32.Generic.vc
ALYacTrojan.Agent.DATX
Cylanceunsafe
ZillyaTrojan.Agent.Win32.920430
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052948f1 )
AlibabaAdWare:Win32/Kryptik.a5c4a241
K7GWTrojan ( 0052948f1 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.36744.CAW@aCDeiFli
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GDVU
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0PB924
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderTrojan.Agent.DATX
NANO-AntivirusRiskware.Win32.Kryptik.ffowfv
AvastWin32:AdwareX-gen [Adw]
TencentTrojan.Win32.Kryptik.gicr
EmsisoftTrojan.Agent.DATX (B)
F-SecureHeuristic.HEUR/AGEN.1317725
DrWebTrojan.Vittalia.13656
VIPRETrojan.Agent.DATX
TrendMicroTROJ_GEN.R002C0PB924
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Malicious PE
JiangminPacked.Katusha.crvp
WebrootPua.Adware.Gen
GoogleDetected
AviraHEUR/AGEN.1317725
VaristW32/S-4131546f!Eldorado
Antiy-AVLGrayWare[Bundler]/Win32.Prepscram
KingsoftWin32.Troj.Generic.a
MicrosoftSoftwareBundler:Win32/Prepscram
XcitiumApplication.Win32.IStartSurf.PS@8c4m91
ArcabitTrojan.Agent.DATX
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Generic
GDataTrojan.Agent.DATX
CynetMalicious (score: 99)
AhnLab-V3PUP/Win32.Bundler.R231192
Acronissuspicious
McAfeeGenericRXFQ-CS!B44E3D7A23DF
MAXmalware (ai score=100)
VBA32BScope.Adware.Prepscram
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!8.8 (TFE:5:zhBg08pibyM)
YandexTrojan.GenAsa!2nO/106Y1aE
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.12118273.susgen
FortinetW32/GenKryptik.DAKE!tr
AVGWin32:AdwareX-gen [Adw]
Cybereasonmalicious.725cc7
DeepInstinctMALICIOUS

How to remove Trojan.Agent.DATX?

Trojan.Agent.DATX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment