Trojan

Trojan.Agent.DFRH (file analysis)

Malware Removal

The Trojan.Agent.DFRH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.DFRH virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by registry key
  • Anomalous binary characteristics

How to determine Trojan.Agent.DFRH?


File Info:

crc32: 19F4B602
md5: 1ccf3bf46280c8b3a8cfc871e3ad5ebb
name: 1CCF3BF46280C8B3A8CFC871E3AD5EBB.mlw
sha1: cb74121b2b57064cfca1e93e1b14d56f96869351
sha256: 238fa945beacb1aeb4e0c27f1b32719bad375bf9e93a788104be402b0f03abf7
sha512: b7a6d3dcf6d75c57071f842bf69c9f1a6629bd9b7974646a64ed60dca6e517cffb109d84d488e1db9cd4e02df25b2a9b0395abb42081d381f4ae174fbbea8a62
ssdeep: 3072:yhsHIFK/rMdbgqmpnHHHHH0fbM5aqSWXKGxbcjCbhw:yFi8gqenHHHHH0XWXKG3C
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1993-2012 Portrait Displays, Inc.
Detailed: pivot-standard-Pivot-standard-R2012-03-15-1729-55
FileVersion: 9.52
CompanyName: Portrait Displays, Inc.
LegalTrademarks: Pivot(R), Pivot Software(R), and Pivot Enabled(R) Are registered trademarks of Portrait Displays, Inc.
ProductName: Pivot Sofware
ProductVersion: 9.52
FileDescription: Pivot Software Support Application
OriginalFilename: wpflip.exe
Translation: 0x0409 0x04e4

Trojan.Agent.DFRH also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Yakes.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen7.57348
ClamAVWin.Dropper.Bunitu-9899448-0
ALYacTrojan.Agent.DFRH
CylanceUnsafe
ZillyaTrojan.Yakes.Win32.69486
SangforVirus.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Bunitu.ali1000105
K7GWTrojan ( 0053d8e61 )
K7AntiVirusTrojan ( 0053d8e61 )
CyrenW32/Trojan.BUF.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.GLET
APEXMalicious
AvastWin32:DangerousSig [Trj]
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Yakes.xlvn
BitDefenderTrojan.Agent.DFRH
NANO-AntivirusTrojan.Win32.Kryptik.fikwkv
MicroWorld-eScanTrojan.Agent.DFRH
TencentMalware.Win32.Gencirc.10ba6560
Ad-AwareTrojan.Agent.DFRH
SophosMal/Generic-S + Mal/Cerber-AM
ComodoTrojWare.Win32.TrojanProxy.Bunitu.FG@7zez5j
BitDefenderThetaGen:NN.ZexaF.34294.xq1@a4C6Sdoi
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.TRICKBOT.SMB.hp
McAfee-GW-EditionTrickbot-FRDP!1CCF3BF46280
FireEyeGeneric.mg.1ccf3bf46280c8b3
EmsisoftTrojan.Agent.DFRH (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Yakes.abeo
AviraHEUR/AGEN.1106153
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.28342D2
MicrosoftTrojanProxy:Win32/Bunitu!rfn
GDataTrojan.Agent.DFRH
AhnLab-V3Trojan/Win32.Emotet.R292987
McAfeeTrickbot-FRDP!1CCF3BF46280
MAXmalware (ai score=99)
VBA32BScope.TrojanProxy.Bunitu
MalwarebytesMalware.AI.1434671637
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.TRICKBOT.SMB.hp
RisingTrojan.Kryptik!1.B397 (CLASSIC)
YandexTrojan.GenAsa!0vy7VcHdmQg
IkarusTrojan-Ransom.Crypted007
FortinetW32/Kryptik.GLWT!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml

How to remove Trojan.Agent.DFRH?

Trojan.Agent.DFRH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment