Trojan

About “Trojan.Agent.DXKD” infection

Malware Removal

The Trojan.Agent.DXKD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.DXKD virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Agent.DXKD?


File Info:

crc32: F2707C34
md5: c722f0a20113bb1488382daefda9a358
name: 1c.jpg
sha1: 4d269f0ec76a564f952c348b32a3b59c34bab2b4
sha256: 3d4d462dbc7dbfd12af693f8176e9fd6814560ed763448fa75fa6dad026567f4
sha512: 534a1acdd94846138086a9912f8c2bcf154e0765f80d0a8432004687c76909fa9ab95adef24b8ec67b10cdff2aa59c50d0bf086e034e3b12f4ea484c7605e991
ssdeep: 24576:IIvEq8jlEBPkNShzxh7QjO+NhXh1l/JFfnE88smv:najiNOsbQjOuXh1lvESw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 2003-2014 Glarysoft Ltd
InternalName: RegDefrag.exe
FileVersion: 5.0.0.14
CompanyName: Glarysoft Ltd
ProductName: Glary Utilities
ProductVersion: 5.0.0.14
FileDescription: Registry Defrag
OriginalFilename: RegDefrag.exe
Translation: 0x0804 0x03a8

Trojan.Agent.DXKD also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.Agent.DXKD
Qihoo-360Generic/Trojan.814
McAfeeTrickbot-FRDP!C722F0A20113
MalwarebytesRansom.Troldesh
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderTrojan.Agent.DXKD
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
TrendMicroRansom.Win32.SHADE.SMA.hp
F-ProtW32/Agent.AZS.gen!Eldorado
SymantecDownloader
ESET-NOD32a variant of Win32/Kryptik.FDEO
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Fsysna-7082626-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Fsysna.a4c28f90
NANO-AntivirusTrojan.Win32.Kryptik.fqnefy
TencentWin32.Trojan.Falsesign.Swuc
Ad-AwareTrojan.Agent.DXKD
EmsisoftTrojan-Ransom.Shade (A)
ComodoMalware@#1iycherp2zb3v
F-SecureTrojan.TR/AD.Troldesh.vpxku
DrWebTrojan.Siggen8.28365
ZillyaTrojan.Fsysna.Win32.17910
Invinceaheuristic
McAfee-GW-EditionTrickbot-FRDP!C722F0A20113
FireEyeGeneric.mg.c722f0a20113bb14
SophosMal/Emotet-Q
SentinelOneDFI – Suspicious PE
CyrenW32/Agent.AZS.gen!Eldorado
JiangminTrojan.Generic.dmfmd
WebrootW32.Trojan.Gen
AviraTR/AD.Troldesh.vpxku
FortinetW32/Kryptik.GLWT!tr
Antiy-AVLTrojan[Ransom]/Win32.Troldesh
Endgamemalicious (high confidence)
ArcabitTrojan.Agent.DXKD
ViRobotTrojan.Win32.S.Ransom.1244336
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/CryptInject.SD!MTB
TACHYONRansom/W32.Shade.1244336
AhnLab-V3Trojan/Win32.Fsysna.C3264970
Acronissuspicious
VBA32Malware-Cryptor.Kirgudu
ALYacTrojan.Ransom.Shade
MAXmalware (ai score=100)
CylanceUnsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.SHADE.SMA.hp
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexTrojan.Fsysna!
IkarusTrojan-Ransom.Crypted007
eGambitPE.Heur.InvalidSig
GDataTrojan.Agent.DXKD
BitDefenderThetaGen:NN.ZexaF.34106.lr1@aWDr8Sib
AVGWin32:Malware-gen
Cybereasonmalicious.20113b
AvastWin32:Malware-gen
MaxSecureTrojan.Malware.7164915.susgen

How to remove Trojan.Agent.DXKD?

Trojan.Agent.DXKD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment