Trojan

Trojan.Agent.DHAN information

Malware Removal

The Trojan.Agent.DHAN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.DHAN virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by registry key

Related domains:

wpad.local-net

How to determine Trojan.Agent.DHAN?


File Info:

name: B5DF9F6882E06A6A0977.mlw
path: /opt/CAPEv2/storage/binaries/22d207f534312154bcf4982d5fac4afe014def6e65d62a35a0d4b7ef5c1668db
crc32: 0FE0B897
md5: b5df9f6882e06a6a0977f2b6ae4b7c42
sha1: eab09ec4a3a090a0ce039d99d93590a8a6cb4daf
sha256: 22d207f534312154bcf4982d5fac4afe014def6e65d62a35a0d4b7ef5c1668db
sha512: fe4363637fd3af87268c819d94ab8a2e88b5f4723b1920c307ae3ad848b15a4d6c0b6e74581d0a6499507a1f142005abf5d54c498a90c9b75869da3e982511e0
ssdeep: 1536:/AZmxWvBPXRymwFCxGKwtSHh+sKyBX830X830X83Zlekon2TNM59KBKGGRQg3nHn:/ABULCxRCkh+sSwn2ZM5MBpGQgXHFJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14A84F521B1F52F57EE8B48B009CDE1F659DBEE717399F2871653F03509303E162A826A
sha3_384: 14dadb8123725fe8fb9d18b13b0f793a1dc10d7e8251a49af5529cfdb9f999f2c2c7fd41f0e3588a6f4983646a48ec68
ep_bytes: e8f8150000e978feffff8bff558bec8b
timestamp: 2018-10-19 03:58:03

Version Info:

CompanyName: Speedbit Ltd.
FileDescription: DAP Error Report
FileVersion: 1, 0, 0, 3
LegalCopyright: Copyright (C) 1999 - 2011 SpeedBit Ltd.
OriginalFilename: dapxrpt.exe
ProductName: DAP Error Report
ProductVersion: 1, 0, 0, 3
Comments: 2599
PrivateBuild: 2599
Translation: 0x0409 0x04b0

Trojan.Agent.DHAN also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.DHAN
FireEyeGeneric.mg.b5df9f6882e06a6a
ALYacTrojan.Agent.DHAN
CylanceUnsafe
ZillyaTrojan.Yakes.Win32.69853
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005380741 )
AlibabaTrojan:Win32/Bunitu.ali1000105
K7GWTrojan ( 005380741 )
Cybereasonmalicious.882e06
CyrenW32/Trojan.BUF.gen!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.GLUW
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.NetStream.gen
BitDefenderTrojan.Agent.DHAN
NANO-AntivirusTrojan.Win32.Yakes.fjjpgg
AvastWin32:DangerousSig [Trj]
TencentMalware.Win32.Gencirc.10cbc62b
Ad-AwareTrojan.Agent.DHAN
EmsisoftTrojan.Agent.DHAN (B)
ComodoTrojWare.Win32.TrojanProxy.Bunitu.FG@7zez5j
DrWebTrojan.Siggen7.57824
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.SHADE.SMB.hp
McAfee-GW-EditionTrickbot-FRDP!B5DF9F6882E0
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
GDataTrojan.Agent.DHAN
JiangminRiskTool.MSIL.ccew
AviraHEUR/AGEN.1117922
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.28A7ECD
ArcabitTrojan.Agent.DHAN
MicrosoftTrojanProxy:Win32/Bunitu!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R437541
Acronissuspicious
McAfeeTrickbot-FRDP!B5DF9F6882E0
VBA32BScope.TrojanProxy.Bunitu
MalwarebytesMalware.AI.2485875449
TrendMicro-HouseCallRansom.Win32.SHADE.SMB.hp
RisingTrojan.Kryptik!1.B397 (CLASSIC)
YandexTrojan.GenAsa!tVai2OHz8L4
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.GLWT!tr
BitDefenderThetaGen:NN.ZexaF.34294.yq1@aGWZsgbi
AVGWin32:DangerousSig [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Agent.DHAN?

Trojan.Agent.DHAN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment