Threat Database Trojans Trojan.Dapato.AG

Trojan.Dapato.AG

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 15,037
Threat Level: 80 % (High)
Infected Computers: 89
First Seen: April 29, 2025
Last Seen: July 19, 2026
OS(es) Affected: Windows

The detection of Trojan.Dapato.AG on your system indicates a potential security threat that requires immediate attention. This type of threat is categorized as a Trojan, which is a broad term for malicious software that disguises itself as legitimate software. Trojans can cause significant harm to your system, including data theft, system crashes, and unauthorized access to your computer.

What Is Trojan.Dapato.AG?

Trojan.Dapato.AG is a type of malware that can infect your system through various means, such as downloading infected software, opening malicious email attachments, or visiting compromised websites. Once installed, it can perform a range of malicious activities, including stealing sensitive information, installing additional malware, and providing unauthorized access to your system.

How Trojan.Dapato.AG Operates

Trojan.Dapato.AG operates by exploiting vulnerabilities in your system's security, allowing it to install and run malicious code without your knowledge or consent. It can also use social engineering tactics to trick you into installing or running the malware. Once installed, it can communicate with its creators, allowing them to control your system remotely and steal sensitive information.

Trojans like Trojan.Dapato.AG can be difficult to detect, as they often disguise themselves as legitimate software or system files. They can also use rootkit techniques to hide their presence from your system's security software. However, most antivirus software can detect and remove Trojans, including Trojan.Dapato.AG, using advanced scanning and removal techniques.

Symptoms of Infection

If your system is infected with Trojan.Dapato.AG, you may notice a range of symptoms, including slow system performance, frequent crashes, and unexpected behavior. You may also notice that your system is running unfamiliar programs or that your browser is being redirected to suspicious websites. Additionally, you may receive alerts from your security software indicating that a threat has been detected.

  • Unexplained system crashes or freezes
  • Slow system performance or sluggish behavior
  • Unfamiliar programs or icons on your desktop
  • Redirected browser searches or suspicious website visits
  • Alerts from your security software indicating a threat detection

How to Remove Trojan.Dapato.AG

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow your security software to run more effectively.
  2. Run a full scan of your system using a reputable antivirus tool, such as SpyHunter, to detect and remove the Trojan.Dapato.AG malware.
  3. Uninstall any suspicious programs or software that may be related to the malware infection.
  4. Reset your browser settings to their default values, including Chrome, Firefox, and Edge, to remove any malicious extensions or add-ons.
  5. Reboot your system and run another full scan to ensure that the malware has been completely removed.

Conclusion

The removal of Trojan.Dapato.AG requires a combination of technical expertise and caution. By following the steps outlined above and using reputable security software, you can effectively remove the malware and prevent future infections. It is essential to remain vigilant and to regularly scan your system for potential threats to ensure the security and integrity of your data.

Analysis Report

General information

Family Name: Trojan.Dapato.AG
Signature status: Hash Mismatch

Known Samples

MD5: 85e351a27900977944c35c8c8cbfca52
SHA1: ed475301e3a70010b69de51527c3ab9fd27e86d7
SHA256: 43B75B7C5459937CB4D936E8AE2CA1A0D2C3491F23E500A14C8CC979A581A3F6
File Size: 3.91 MB, 3909408 bytes
MD5: 4a74e705fc416e2f274f95a2d6c8f85a
SHA1: 495c425ef1697e3556864bf3eb63c4e95bb1f19b
SHA256: 31F3DF324455771318986FF3B2A239FAED9DB07A8AB15C6BBB26EB98B47A2D96
File Size: 6.22 MB, 6217504 bytes
MD5: ddeb1e4a71ecd457f3143f33454c2d6f
SHA1: 9ee91183c32d62b410c0d069695f887319c22ef6
SHA256: 1E63E136E278FE23740869FC1DD4DC4EC5FB1DEB76B38F471F5560EFC51C2329
File Size: 7.33 MB, 7326496 bytes
MD5: 051f730cd8040cd08b816b35f47d87af
SHA1: f75a220add87191835f8652e2d64d11403513d74
SHA256: 958CB7AA579F6A4A158451D072B77C1332CCBB2F577B961916BC476044561C28
File Size: 7.87 MB, 7873312 bytes
MD5: 4b5d6ba934ddf4f122f88b5187d5ab31
SHA1: 74efc16d7224b9c41a16947ec724d529da1abf23
SHA256: 60D9115E3DA93A8E309129B9B76C3C3014A12AA7ABD9AB6BA63053D0DE660B90
File Size: 7.37 MB, 7371552 bytes
Show More
MD5: 18f17e832a2003dd42431a5fbad1304e
SHA1: e098f9752dc97bc66e1199ea6f00b803a6a17f5c
SHA256: 87764906FD110214A3A99040AE16FEBCAE78EB9FD48C7823008F5C0DB1895E77
File Size: 6.06 MB, 6060320 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Version 5.3.0.0
Internal Name
  • 2Pri nter
  • 2Printer
Legal Copyright В© fCoder SIA 2016. All rights reserved.
Original Filename 2Printer.exe
Product Name 2Printer
Product Version 5.3.0.0

Digital Signatures

Signer Root Status
Corel Corporation VeriSign Class 3 Code Signing 2004 CA Hash Mismatch

File Traits

  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 1,918
Potentially Malicious Blocks: 2
Whitelisted Blocks: 1,913
Unknown Blocks: 3

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Banker.TH
  • Banload.XL
  • Brute.LBA
  • Delf.XB
  • Injector.FGSA
Show More
  • Injector.FHBB
  • Injector.FHBC
  • Injector.FHBD
  • Injector.FHBE
  • Injector.GDSB
  • Injector.GSD
  • Injector.KDF
  • Injector.KDG
  • Injector.KFAD
  • Injector.KSJ
  • Injector.PMB
  • Injector.PMC
  • Injector.XN
  • Kryptik.CLBB
  • Kryptik.FTSB
  • Kryptik.GSJ
  • Sadenav.B
  • Startpage.GA
  • Trojan.Kryptik.Gen.EKG
  • Trojan.Kryptik.Gen.EKL

Files Modified

File Attributes
c:\users\user\appdata\local\temp\svc5704.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\svchost015.exe Read Data,Read Attributes,Synchronize,Write Data

Windows API Usage

Category API
User Data Access
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Trending

Most Viewed

Loading...