Trojan

Trojan.Agent.DDKU removal instruction

Malware Removal

The Trojan.Agent.DDKU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.DDKU virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
luoye46.3vfree.com

How to determine Trojan.Agent.DDKU?


File Info:

crc32: 4F074DA8
md5: b531082da2e8821ac905cb5c5cb9d04f
name: B531082DA2E8821AC905CB5C5CB9D04F.mlw
sha1: bf8c5c851ab0e111f59ad118f1e3f85a1279eb01
sha256: 0f197333a5e32a2f22ee3ce118b4f3840bb91dfe4ef476806e5219ed0c1af7e8
sha512: a331eb5b96616a4d77dcd38d75e14e3ece07ea92a6a342187858c356d54ba25b6098180b0ca2062e9abab277c1bf9fba5bf2c7b79dee899503a32af210747ada
ssdeep: 24576:AhNDL9/AdhhiARLHb6lKndA8yWXvpEAloVZM6j7:A/dAdhxRrb6lKu8HdloVxn
type: MS-DOS executable, MZ for MS-DOS

Version Info:

0: [No Data]

Trojan.Agent.DDKU also known as:

BkavW32.AIDetectVM.malware1
K7AntiVirusAdware ( 00506e8d1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader27.938
CynetMalicious (score: 100)
CAT-QuickHealRisktool.Flystudio.16886
McAfeeArtemis!B531082DA2E8
CylanceUnsafe
ZillyaTool.Agent.Win32.26286
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaHackTool:Win32/QQPass.c77dbb97
K7GWAdware ( 00506e8d1 )
Cybereasonmalicious.da2e88
TrendMicroTROJ_GEN.R002C0GHL20
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.QQPass.OZV
APEXMalicious
AvastWin32:Malware-gen
KasperskyHackTool.Win32.Agent.ahtk
BitDefenderTrojan.Agent.DDKU
NANO-AntivirusTrojan.Win32.Dwn.fhofcp
MicroWorld-eScanTrojan.Agent.DDKU
TencentWin32.Hacktool.Agent.Pdlp
Ad-AwareTrojan.Agent.DDKU
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
BitDefenderThetaGen:NN.ZexaF.34186.nnW@a8UuOIlb
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
FireEyeGeneric.mg.b531082da2e8821a
SophosGeneric PUA LP (PUA)
SentinelOneDFI – Suspicious PE
JiangminHackTool.Agent.dbv
WebrootW32.Trojan.Agent.Gen
MicrosoftTrojan:Win32/Occamy.C0F
ArcabitTrojan.Agent.DDKU
AegisLabHacktool.Win32.Agent.3!c
ZoneAlarmHackTool.Win32.Agent.ahtk
GDataTrojan.Agent.DDKU
TACHYONTrojan/W32.Agent.1277440.V
VBA32BScope.Trojan.Tiggre
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0GHL20
RisingTrojan.Injector!1.A1C3 (CLOUD)
YandexRiskware.HackTool!qc+vL5RJ2mo
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic_PUA_LP
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Agent.DDKU?

Trojan.Agent.DDKU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment