Trojan

Trojan.Agent.DCER (file analysis)

Malware Removal

The Trojan.Agent.DCER is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.DCER virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Sniffs keystrokes
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Agent.DCER?


File Info:

crc32: 332BC989
md5: c599b8c932e5d9c2c9313a0c3df64559
name: C599B8C932E5D9C2C9313A0C3DF64559.mlw
sha1: d6da4bf7132876adece6323d5b235c55aabd57a0
sha256: c78cb37297cbf33db078582f3895c03338d1e37771b1cd2c1f5d0ad0e2f44710
sha512: bc0a6732694d556f0ab9ca757c5203df42cf2c054a8e4a2ab661cada553f2a692287b824f82ae387b84ccde3eb23f8d6dc347df5a7df4aa4534a21fe35bf258e
ssdeep: 6144:+afsiuvAQ+tTm6cyERSiytj71cWE4jKS6vZ9BTD:7CvAQ+q6ctRt636WfjOnBTD
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan.Agent.DCER also known as:

BkavW32.FamVT.ScarC.Trojan
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader22.23546
MicroWorld-eScanTrojan.Agent.DCER
CAT-QuickHealWorm.Macoute.A8
McAfeeGenericRXAH-QS!C599B8C932E5
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004ba8531 )
BitDefenderTrojan.Agent.DCER
K7GWTrojan ( 004ba8531 )
Cybereasonmalicious.932e5d
BitDefenderThetaGen:NN.ZexaF.34590.ACW@aqqtY3ji
CyrenW32/Trojan.KZWZ-0325
SymantecW32.Pholdicon
APEXMalicious
AvastWin32:Crypt-KOW [Trj]
ClamAVWin.Malware.Zusy-6888246-0
KasperskyTrojan.Win32.Agentb.bqyr
NANO-AntivirusTrojan.Win32.Agent.erqhdu
TencentTrojan.Win32.Keylogger.aa
Ad-AwareTrojan.Agent.DCER
SophosMal/Generic-R + Troj/Scar-CM
ComodoTrojWare.Win32.Scar.WRM@6hdckm
F-SecureTrojan.TR/Crypt.XPACK.Gen4
BaiduWin32.Virus.Virut.gen
ZillyaTrojan.Scar.Win32.54986
TrendMicroWORM_MACOUTE.SMJ1
McAfee-GW-EditionBehavesLike.Win32.Generic.gm
FireEyeGeneric.mg.c599b8c932e5d9c2
EmsisoftTrojan.Agent.DCER (B)
SentinelOneStatic AI – Malicious PE
JiangminWin32/Virut.bv
eGambitUnsafe.AI_Score_99%
AviraTR/Crypt.XPACK.Gen4
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Scar
MicrosoftWorm:Win32/Macoute
GridinsoftTrojan.Win32.Agent.bot!s1
ArcabitTrojan.Agent.DCER
SUPERAntiSpywareWorm.PasswordStealer/Variant
ZoneAlarmTrojan.Win32.Agentb.bqyr
GDataTrojan.Agent.DCER
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Scar.R160138
Acronissuspicious
VBA32TScope.Malware-Cryptor.SB
ALYacTrojan.Agent.DCER
MalwarebytesPioneer.Virus.FileInfector.DDS
PandaTrj/Genetic.gen
ESET-NOD32Win32/Virut.NBP
TrendMicro-HouseCallWORM_MACOUTE.SMJ1
RisingWorm.Macoute!1.A746 (CLOUD)
YandexTrojan.GenAsa!53PMqSgQMYw
IkarusWin32.Outbreak
MaxSecureTrojan.Agentb.BQYR
FortinetW32/Agent.NML!tr
AVGWin32:Crypt-KOW [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/QVM02.0.9617.Malware.Gen

How to remove Trojan.Agent.DCER?

Trojan.Agent.DCER removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment