Trojan

Should I remove “Trojan.Agent.DYAA”?

Malware Removal

The Trojan.Agent.DYAA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.DYAA virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • Authenticode signature is invalid

How to determine Trojan.Agent.DYAA?


File Info:

name: 0DA1157A77723EB193AB.mlw
path: /opt/CAPEv2/storage/binaries/6a90ed9e4f7b768a6de5defc0530ed93b3034de6d47cc63b5e9ef05f05081b1b
crc32: 31FF325B
md5: 0da1157a77723eb193ab8b68a85708a2
sha1: 6f1592259b2a9ff739b1703a7a7d2ebd2a5c56d0
sha256: 6a90ed9e4f7b768a6de5defc0530ed93b3034de6d47cc63b5e9ef05f05081b1b
sha512: c0e2833069de9f40cf1452db04d4145afacf7c418c7a790ef3f8563007efa7c4af16a3f36978daeb808a5af21882318d60ab5b5e069e5bbb15cef1aa00ee1964
ssdeep: 12288:p51x08TRBBWGcS9XynvI6XsR+rEhAPJ2F8kmjI4eVYaH892LgZgjp4602zmgWYFo:p51xrsGcS9in6bxcqbFeV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A6350802A20205B3D45120B6C04A7BA54764CFB92F63E2E3FE58F016FA72BC655776F9
sha3_384: 390623bdc37e6c026bc63f2a4b29243983edca0f2dae50e58c8b076a4a6e144883d7a060b0e1a1890e80612b0c5a78f7
ep_bytes: 558bec6aff6820b2400068e46f400064
timestamp: 2002-07-11 04:39:26

Version Info:

0: [No Data]

Trojan.Agent.DYAA also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Daws.mzM4
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Agent.DYAA
ClamAVWin.Trojan.Iparm-1
FireEyeTrojan.Agent.DYAA
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Agent.DYAA
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaVirus:Win32/Ipamor.19c5
K7GWVirus ( 0040f5921 )
K7AntiVirusVirus ( 0040f5921 )
CyrenW32/Ipamor.A.gen!Eldorado
SymantecW32.HLLP.Ipamor
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
BitDefenderTrojan.Agent.DYAA
SUPERAntiSpywareTrojan.Agent/Gen-Ipamor
AvastWin32:Ipamor
TencentVirus.Win32.Viking.aak
TACHYONWorm/W32.Ipamor.Zen.D
EmsisoftTrojan.Agent.DYAA (B)
DrWebWin32.HLLP.Iparmor.35858
VIPRETrojan.Agent.DYAA
McAfee-GW-EditionBehavesLike.Win32.Ipamor.th
SophosW32/Ipamor-B
SentinelOneStatic AI – Malicious PE
GDataWin32.Virus.Ipamor-Main.A
JiangminTrojan.Generic.ghobc
Antiy-AVLVirus/Win32.Ipamor.g
XcitiumVirus.Win32.Ipamor.G@8j5juk
ArcabitTrojan.Agent.DYAA
MicrosoftVirus:Win32/Ipamor.A
GoogleDetected
AhnLab-V3Win32/Ipamor.D.X1356
Acronissuspicious
McAfeeW32/Ipamor
MAXmalware (ai score=89)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
RisingVirus.Ipamor!8.3BC (CLOUD)
IkarusVirus.Win32.Ipamor
MaxSecureBanker.Banbra.vwsb
FortinetW32/Agent.DYAA!tr
AVGWin32:Ipamor
Cybereasonmalicious.a77723
DeepInstinctMALICIOUS

How to remove Trojan.Agent.DYAA?

Trojan.Agent.DYAA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment