Trojan

About “Trojan.Agent.DKGZ” infection

Malware Removal

The Trojan.Agent.DKGZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.DKGZ virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to delete or modify volume shadow copies
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Attempts to stop active services
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Attempts to disable System Restore
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Agent.DKGZ?


File Info:

name: EBC1AD548B596AE1290F.mlw
path: /opt/CAPEv2/storage/binaries/ebdb4bedb3d0dfa525eaf339dc6a3485c82f88f8f31879db1ff24892a81a7703
crc32: A21ECCD8
md5: ebc1ad548b596ae1290f68d1c88409b0
sha1: 03539b7f0afde14e213b9bafaa47c0c4b66b0de9
sha256: ebdb4bedb3d0dfa525eaf339dc6a3485c82f88f8f31879db1ff24892a81a7703
sha512: a851cb69d9bf2fcf32487c354cc01a4d465f26b4b80628dccd3da8cc6493b005f6d8ae386fd5d32144d67fe719a1de73c50b10cc8cf52f471308bd4690c0368f
ssdeep: 6144:V6tMTrkAFAARDEIdhpAe9MuLZ6YHJxTjjmDRhqsBSzvesxDhAerqdYXyPKMBx78R:V6tMPkyAARDvhpVZ6YSEz2sxDheAwKa2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B1849DE46791C835F7B713B88DA852AC1D3EBD716BA490CB52C825EB52269D78C3C343
sha3_384: d4e9440303456452bbc5588c14c3540b3f7499938ae7693c5ce4c11d72dcf32a050ca421835a632eda34d6aa0ab7f358
ep_bytes: 8bff558bece886650000e8110000005d
timestamp: 2015-06-11 15:31:04

Version Info:

Comments:
CompanyName: Photodex Corporation
FileDescription: Resource File Conversion
LegalCopyright: Copyright ©2003-2015 Photodex Corporation
LegalTrademarks: Photodex Corporation
ProductName: Resource File Conversion
ProductVersion: 1.2.0.7
SpecialBuild: 1.2.0.7
Translation: 0x0409 0x04b0

Trojan.Agent.DKGZ also known as:

LionicTrojan.Win32.Generic.mmcn
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.DKGZ
FireEyeGeneric.mg.ebc1ad548b596ae1
CAT-QuickHealTrojan.Generic.B4
McAfeeArtemis!EBC1AD548B59
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Kryptik.DLTY
K7AntiVirusTrojan ( 0055dd191 )
AlibabaRansom:Win32/Blocker.32555619
K7GWTrojan ( 0055dd191 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34182.xy0@aKseolci
VirITTrojan.Win32.Crypt4.ASFQ
SymantecRansom.Cryptodefense
ESET-NOD32a variant of Win32/Kryptik.DLTY
TrendMicro-HouseCallTROJ_CRYPWALL.XXRM
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Blocker.hgig
BitDefenderTrojan.Agent.DKGZ
NANO-AntivirusTrojan.Win32.Blocker.dstren
TencentWin32.Trojan.Blocker.Anzd
SophosMal/Generic-S + Mal/Generic-L
ComodoMalware@#82gxf20nq6g9
ZillyaTrojan.Kryptik.Win32.750211
TrendMicroTROJ_CRYPWALL.XXRM
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.Agent.DKGZ (B)
IkarusTrojan.Win32.Crypt
JiangminTrojan.Blocker.ost
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1113271
Antiy-AVLTrojan/Generic.ASMalwS.1193A97
KingsoftWin32.Heur.KVM003.a.(kcloud)
MicrosoftRansom:Win32/Crowti
ZoneAlarmTrojan-Ransom.Win32.Blocker.hgig
GDataTrojan.Agent.DKGZ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Dynamer.R153026
ALYacTrojan.Agent.DKGZ
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Shade
PandaTrj/Genetic.gen
APEXMalicious
RisingRansom.Crowti!8.37D (CLOUD)
YandexTrojan.Blocker!lmSAvWE8tmg
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetW32/Kryptik.DLVX!tr
AVGWin32:GenMalicious-KXI [Trj]
Cybereasonmalicious.48b596
AvastWin32:GenMalicious-KXI [Trj]

How to remove Trojan.Agent.DKGZ?

Trojan.Agent.DKGZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment