Trojan

Trojan.Agent.DDKH removal guide

Malware Removal

The Trojan.Agent.DDKH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.DDKH virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.Agent.DDKH?


File Info:

crc32: 0D18F233
md5: 637237f85f1258c27f63b2b3b93b9cdd
name: 637237F85F1258C27F63B2B3B93B9CDD.mlw
sha1: c01e66a4f0732fabea3d9ff1563836d5e54809ae
sha256: 239c6544db78bc1970deaa2ed97c1e5980e1329f278c8a0226a4fb288991b6a7
sha512: 572d9605a10f2d1524671897eba3394ead68bdcf937c70a9d3d069545a58a9800efb41f0ec79c2d07a2bbfd50627c31343877a061b57dd51c98da3d2d9799f83
ssdeep: 24576:7a96L7dsI3S9Gb7vKr9S4whZIw2ezam7Xu1pPY:SPcKrbyzaC+1RY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: AHRepair.exe
FileVersion: 3.1.1088.33
Comments: free installer
ProductName: Framework 3.20 Setup
ProductVersion: 3.1.1088.33
FileDescription: Framework 3.20 Setup
OriginalFilename: AHRepair.exe
Translation: 0x0409 0x04b0

Trojan.Agent.DDKH also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053b5071 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.DDKH
CAT-QuickHealTrojan.Chapak.S3456034
ALYacTrojan.Agent.DDKH
MalwarebytesTrojan.MalPack
ZillyaTrojan.GenericKD.Win32.165789
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderTrojan.Agent.DDKH
K7GWTrojan ( 0053b0121 )
Cybereasonmalicious.85f125
BitDefenderThetaGen:NN.ZexaF.34294.Ir0@aGJvA6mi
CyrenW32/Trojan.CHZ.gen!Eldorado
SymantecPUA.ICLoader
ESET-NOD32a variant of Win32/Kryptik.GKCF
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Miner.5461401b
NANO-AntivirusTrojan.Win32.Ekstak.fhmikq
TencentMalware.Win32.Gencirc.10cc5d41
Ad-AwareTrojan.Agent.DDKH
ComodoApplication.Win32.ICLoader.GS@84429a
DrWebTrojan.InstallCube.3673
FireEyeGeneric.mg.637237f85f1258c2
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Ekstak.prh
AviraTR/Crypt.Agent.lqzsm
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.27D57BF
TACHYONTrojan/W32.Ekstak.1609728.G
AhnLab-V3PUP/Win32.ICLoader.R235442
Acronissuspicious
VBA32BScope.Trojan.Ekstak
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.GenAsa!+6/t/hSaL0U
IkarusPUA.ICLoader
FortinetW32/CoinMiner.GYQC!tr
PandaTrj/Genetic.gen

How to remove Trojan.Agent.DDKH?

Trojan.Agent.DDKH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment