Trojan

How to remove “Trojan.Agent.DSNT”?

Malware Removal

The Trojan.Agent.DSNT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.DSNT virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Mimics the system’s user agent string for its own requests
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • A named pipe was used for inter-process communication
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • Enumerates running processes
  • A process created a hidden window
  • Access the NetLogon registry key, potentially used for discovery or tampering
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Detects Bitdefender Antivirus through the presence of a library
  • Behavioural detection: Injection (inter-process)
  • Steals private information from local Internet browsers
  • A system process is generating network traffic likely as a result of process injection
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • CAPE detected the QakBot malware family
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Clears web history
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Agent.DSNT?


File Info:

name: 26CD8E7DB074EF9D560B.mlw
path: /opt/CAPEv2/storage/binaries/4119b768d3d5753b03999b6d823ffbd4266c10087ffbeb27bc8c0ed9411f7494
crc32: BD8E77B2
md5: 26cd8e7db074ef9d560b820adbfe2bdb
sha1: 73be2b03c3a320ff0c6480f28f5761b2783fc609
sha256: 4119b768d3d5753b03999b6d823ffbd4266c10087ffbeb27bc8c0ed9411f7494
sha512: 94c63f313c176132cbd1dcb51cf2bfcd9f2d3bec7389a6420ce3f30ca0062a1dc2b94d00ec1a5d705d52cd90df5ab282a4c3b46d748159f77204487aba11ad64
ssdeep: 24576:rO86T9HtJN1jAEn60rcU9puXG+qRQFHbfni25:PKz7AEh4OdGT5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10965AE37E482B883EE75B87C99D08B55DECFE8131026794CE9C55C621C1F8AA0D7E867
sha3_384: 03a07dbba381575beda10ca9143c85607cba36b79ff320af66b6382c8683f2c63cf9c883207bb8d0dbc8524e62c1b240
ep_bytes: b8902454008b0d2cc040008945fc8b55
timestamp: 2019-03-27 09:08:44

Version Info:

0: [No Data]

Trojan.Agent.DSNT also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebBackDoor.Qbot.489
MicroWorld-eScanTrojan.Agent.DSNT
FireEyeGeneric.mg.26cd8e7db074ef9d
McAfeeW32/PinkSbot-FS!26CD8E7DB074
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0054ab451 )
AlibabaTrojan:Win32/Kryptik.577f6856
K7GWTrojan ( 0054ab451 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.34114.wvW@aCS7Twhi
CyrenW32/Kryptik.AJA.gen!Eldorado
SymantecW32.Qakbot!gen20
ESET-NOD32a variant of Win32/Kryptik.GRKI
TrendMicro-HouseCallTROJ_GEN.R002C0CKS21
Paloaltogeneric.ml
ClamAVWin.Malware.Qbot-6958170-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.DSNT
NANO-AntivirusTrojan.Win32.GenKryptik.foobft
AvastWin32:BankerX-gen [Trj]
TencentMalware.Win32.Gencirc.10b495a8
Ad-AwareTrojan.Agent.DSNT
EmsisoftTrojan.Agent.DSNT (B)
ComodoTrojWare.Win32.Skeeyah.KI@83izpr
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0CKS21
McAfee-GW-EditionBehavesLike.Win32.Generic.th
SophosMal/Generic-R + Troj/Qbot-ES
IkarusTrojan.Win32.Krypt
GDataWin32.Trojan-Spy.Emotet.CO
JiangminTrojan.Generic.dddyn
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1201383
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.2AFF539
GridinsoftRansom.Win32.Skeeyah.oa
MicrosoftTrojan:Win32/Qbot
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C3129715
Acronissuspicious
ALYacTrojan.Agent.DSNT
VBA32BScope.Trojan.Fuerboos
MalwarebytesBackdoor.Qbot
APEXMalicious
RisingTrojan.Generic@ML.94 (RDML:RbRFO7pWS2hGoL7Xx90u0Q)
YandexTrojan.GenAsa!t1o3saVWSPU
SentinelOneStatic AI – Malicious PE
FortinetW32/GenKryptik.DDRU!tr
AVGWin32:BankerX-gen [Trj]
Cybereasonmalicious.db074e
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.7164915.susgen

How to remove Trojan.Agent.DSNT?

Trojan.Agent.DSNT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment