Trojan

Trojan.Agent.DAZC (file analysis)

Malware Removal

The Trojan.Agent.DAZC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.DAZC virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Agent.DAZC?


File Info:

name: E36773EA2A2B3CB814BA.mlw
path: /opt/CAPEv2/storage/binaries/22f63bbef2a22c40b52487a3e821a2f3623e4a2fe93734f6758a61dbfda30060
crc32: 95B4D850
md5: e36773ea2a2b3cb814ba9890ab1771f0
sha1: c7ccaf0f606205d5d22a4c0314ea8200db04efa4
sha256: 22f63bbef2a22c40b52487a3e821a2f3623e4a2fe93734f6758a61dbfda30060
sha512: 53c030c9b640e5be92ba3b7097c458673eadb77cc48708cdd68d58ba6925d1ed191670075a19926726108d292839772d90ff835a5a023ca97c9f27202746a75b
ssdeep: 24576:4jf1upZGh9Z3xmERkmKQDNSCn2+Kn5rKm8qgyjBp:4jfgsxRRxYT+rqg2Bp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D67512A5C1CCE922F5B259F8389081562722FF33997B5B2736E43DDBC834190BA74E91
sha3_384: cdc9522b44ddf48cc5f0c05e9d756cd2348df879fa5a468c814c4a69c1dd0930802907e94b804d9f7576492f23f5dda8
ep_bytes: 558bec81ec44020000c745bc0a090000
timestamp: 2015-04-24 00:53:36

Version Info:

ProductVersion: 1.8.2.0
CompanyName: ©Oehvietreuted mynovenenaa
OriginalFilename: nedat.exe
ProductName: NEDAT
InternalName: NEDAT.EXE
FileVersion: 1.8.2.0
LegalCopyright: ©Oehvietreuted mynovenenaa
Translation: 0x0409 0x04e4

Trojan.Agent.DAZC also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.StartSurf.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.DAZC
FireEyeGeneric.mg.e36773ea2a2b3cb8
ALYacTrojan.Agent.DAZC
Cylanceunsafe
ZillyaTrojan.Agent.Win32.904082
SangforTrojan.Win32.Save.a
AlibabaAdWare:Win32/IStartSurf.c8e5051e
Cybereasonmalicious.a2a2b3
BitDefenderThetaGen:NN.ZexaF.36802.Lz0@a0jVcrni
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/IStartSurf.BF potentially unwanted
APEXMalicious
BitDefenderTrojan.Agent.DAZC
NANO-AntivirusTrojan.Win32.Vittalia.feungt
F-SecureTrojan.TR/Crypt.EPACK.Gen2
DrWebTrojan.Vittalia.13656
VIPRETrojan.Agent.DAZC
TrendMicroTROJ_GEN.R002C0PB624
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
IkarusPUA.Win32.Dlhelper
JiangminAdWare.StartSurf.ehh
GoogleDetected
AviraTR/Crypt.EPACK.Gen2
Antiy-AVLTrojan/Win32.TSGeneric
Kingsoftmalware.kb.a.1000
XcitiumMalCrypt.Indus!@1qrzi1
ArcabitTrojan.Agent.DAZC
ZoneAlarmnot-a-virus:AdWare.Win32.StartSurf.bwie
CynetMalicious (score: 99)
AhnLab-V3Adware/Win32.StartSurf.R231949
VBA32BScope.Trojan.Vittalia
MAXmalware (ai score=97)
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0PB624
YandexTrojan.GenAsa!Q74oRB3dmOU
SentinelOneStatic AI – Malicious PE
FortinetW32/GenKryptik.CFOO!tr
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_60% (W)
alibabacloudAdWare:Win/StartSurf.bwie

How to remove Trojan.Agent.DAZC?

Trojan.Agent.DAZC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment