Spy Trojan

How to remove “Trojan-Spy.Win32.Agent.dawl”?

Malware Removal

The Trojan-Spy.Win32.Agent.dawl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Agent.dawl virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan-Spy.Win32.Agent.dawl?


File Info:

name: AC8C0C8813436A01AECD.mlw
path: /opt/CAPEv2/storage/binaries/1f53bacba63366bc3d41aa0bb7c6be0a27094ffcb67cfe9a60f1cbb6a83edc5b
crc32: C5FA7C74
md5: ac8c0c8813436a01aecd598601806342
sha1: 3fd070cf25479fb1286fcabd846a083687e6e83a
sha256: 1f53bacba63366bc3d41aa0bb7c6be0a27094ffcb67cfe9a60f1cbb6a83edc5b
sha512: 49e63f32c4027362ea5aced32a78d46395f5b4057836122694033c66f844faafb5105095b5790258642053c1e5d6e30ce300da74fa6aa25638dde0b7957be6a0
ssdeep: 12288:lUzeWoc//////Z1rFIGEXdQcxCuNklTtNbMPhEMtAE45vQdNp9zhDpp8vf3MqFDY:RWoc//////Z1ULibMPhEM2EBdLtz2vkD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T108F47D22F2808637C1277639CC2792D96576BF113B2438863EF57E4C9F356923A1A2D7
sha3_384: 5adefd0bf751ab40c43fb20172fb481d6d36908f78c7ad4c00603a7e05ff5a88c2391c0a311e723b83d91ac74a1d9f02
ep_bytes: 558bec83c4f0b894920951e8c8d4f6ff
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName:
FileDescription:
FileVersion: 1.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0410 0x04e4

Trojan-Spy.Win32.Agent.dawl also known as:

MicroWorld-eScanTrojan.GenericKD.33368397
FireEyeGeneric.mg.ac8c0c8813436a01
McAfeeGenericRXCZ-BJ!AC8C0C881343
CylanceUnsafe
AlibabaTrojanSpy:Win32/Generic.c863713a
Cybereasonmalicious.813436
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Agent.dawl
BitDefenderTrojan.GenericKD.33368397
TencentWin32.Trojan-spy.Agent.Lpbo
Ad-AwareTrojan.GenericKD.33368397
SophosMal/Generic-S
F-SecureTrojan.TR/Spy.Agent.uxgoy
DrWebWin32.HLLW.Phorpiex.875
ZillyaTrojan.Agent.Win32.1297303
TrendMicroTROJ_GEN.R002C0PKK21
McAfee-GW-EditionBehavesLike.Win32.Dropper.bh
EmsisoftTrojan.GenericKD.33368397 (B)
GDataTrojan.GenericKD.33368397
JiangminTrojanSpy.Agent.abtl
eGambitGeneric.Trojan
AviraTR/Spy.Agent.uxgoy
MAXmalware (ai score=58)
Antiy-AVLTrojan[Spy]/Win32.Agent
ViRobotTrojan.Win32.Z.Agent.766464.BO
MicrosoftTrojan:Win32/Occamy.C1F
CynetMalicious (score: 99)
BitDefenderThetaGen:NN.ZelphiF.34294.UK0@aqi307lG
ALYacTrojan.GenericKD.33368397
VBA32TrojanSpy.Agent
MalwarebytesMalware.Heuristic.1006
TrendMicro-HouseCallTROJ_GEN.R002C0PKK21
YandexTrojanSpy.Agent!VuZVHgIecTU
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan-Spy.Win32.Agent.dawl?

Trojan-Spy.Win32.Agent.dawl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment