Trojan

Trojan.Agent.DWMQ (file analysis)

Malware Removal

The Trojan.Agent.DWMQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.DWMQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Uses Windows utilities to enumerate running processes
  • Authenticode signature is invalid
  • Attempts to disable Windows Error Reporting
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Agent.DWMQ?


File Info:

name: 6782E0184B5B4E635C0B.mlw
path: /opt/CAPEv2/storage/binaries/27c393fde99a965bf320ee23a12e03fb061b81d01102b9788eac1f09e97f5a79
crc32: 9EF7E63A
md5: 6782e0184b5b4e635c0b60426b625389
sha1: 5f51ab9419d9f3aff6732afae36c531f737c273d
sha256: 27c393fde99a965bf320ee23a12e03fb061b81d01102b9788eac1f09e97f5a79
sha512: e61eb981bc525e4c1a912864e53a6e1f1dd2b4e1e9ca1c8b24ed29ab29b0f511d08053d343cfa4a2b94dc0f035798a54333af04617cec6f28a7e9a37e5c489e1
ssdeep: 98304:A/ZnXnUlY5HQ0MdbrZsdP/I3bmhdZbM0TDuAR63hH0gdvNfFG0Cr3fP:AZnUj1o5/ILZ0fu/3hUg7s0+vP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T198560180BB82D071CC6A0CF9506662B65F749D18BB27BAD384A87D48D9B32F0567D3CD
sha3_384: c95eb9589771770303ab9fceb19e10d61f24df42b48b54ec47081bb936f6b97f6c4dd30a461982568c2c4db07ec88e35
ep_bytes: e872030000e936fdffff8bff558bec8b
timestamp: 2008-11-10 09:40:35

Version Info:

0: [No Data]

Trojan.Agent.DWMQ also known as:

BkavW32.Common.7BE3D941
LionicTrojan.Win32.Vimditator.4!c
MicroWorld-eScanTrojan.Agent.DWMQ
FireEyeTrojan.Agent.DWMQ
McAfeeArtemis!6782E0184B5B
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.Vimditator.Win32.492
SangforTrojan.Win32.Vimditator.V9pi
AlibabaTrojan:Win32/Vimditator.efec6a91
Cybereasonmalicious.419d9f
SymantecTrojan.Gen.MBT
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Generik.HDNFPYI
APEXMalicious
KasperskyTrojan.Win32.Vimditator.abxo
BitDefenderTrojan.Agent.DWMQ
AvastWin32:Malware-gen
EmsisoftTrojan.Agent.DWMQ (B)
VIPRETrojan.Agent.DWMQ
TrendMicroTROJ_GEN.R002C0WGE23
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
GDataTrojan.Agent.DWMQ
ArcabitTrojan.Agent.DWMQ
ZoneAlarmTrojan.Win32.Vimditator.abxo
MicrosoftTrojan:Win32/Wacatac.A!ml
VBA32Trojan.Vimditator
ALYacTrojan.Agent.DWMQ
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0WGE23
TencentWin32.Trojan.Vimditator.Jtgl
MaxSecureTrojan.Malware.73764138.susgen
FortinetW32/Vimditator.ABXO!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Agent.DWMQ?

Trojan.Agent.DWMQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment