Threat Database Trojans Trojan Horse Agent3.AYIB

Trojan Horse Agent3.AYIB

By GoldSparrow in Trojans

Threat Scorecard

Popularity Rank: 4,031
Threat Level: 80 % (High)
Infected Computers: 39,974
First Seen: December 7, 2011
Last Seen: October 14, 2025
OS(es) Affected: Windows

Trojan Horse Agent3.AYIB is a dangerous Trojan enters the targeted computer system bundled with other malware threats and executes malicious activities without the user's permission and knowledge. Once installed onto a compromised PC system, Trojan Horse Agent3.AYIB will change your desktop background and display various false warning messages. Trojan Horse Agent3.AYIB is able to redirect its victims to malicious websites while they are browsing the web. Trojan Horse Agent3.AYIB spreads via malicious spam email attachments. Uninstall Trojan Horse Agent3.AYIB as soon as possible.

SpyHunter Detects & Remove Trojan Horse Agent3.AYIB

File System Details

Trojan Horse Agent3.AYIB may create the following file(s):
# File Name MD5 Detections
1. bb18d23bf4be9333adacb8661d03908c3e465c5a3b778170b18cc53077bccb95.exe 76cc8d23dc9c01388e0ae17a067ef80c 1
2. C:WindowsSystem32fake dwm.exe
3. C:Program Files[RANDOM CHARACTERS].exe
4. C:WindowsSystem32fake wuauclt.exe
5. C:Windowsfake explorer.exe
6. C:WindowsSystem32fake taskhost.exe
7. C:Documents and SettingsUser nameLocalSettingsTemporary Internet FilesContent[RANDOM CHARACTERS]

Registry Details

Trojan Horse Agent3.AYIB may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINESYSTEMControlSet001EnumRootLEGACY_MYNAME000Control
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices[RANDOM CHARACTERS]
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun[RANDOM CHARACTERS].exe

Analysis Report

General information

Family Name: Trojan.Coinminer.GCA
Signature status: Root Not Trusted

Known Samples

MD5: f029a33d2cbca29a93f17d33e16137c9
SHA1: 26dc1f7c43340b275e8660e35ba0a3a7284041bd
SHA256: 4711B6E4CA90B6DEAAE343DECA4B86C1DAEA6DB145ABCE7B9E1ADE272A2133E5
File Size: 3.21 MB, 3209448 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Massive Computing, Inc.
File Description Massive library
File Version 0.10.2.0
Internal Name Massive.dll
Legal Copyright Copyright 2019–2021 Massive Computing, Inc.
Original Filename Massive.dll
Product Name Massive
Product Version 0.10.0

Digital Signatures

Signer Root Status
Bit Guardian GmbH Sectigo Public Code Signing Root R46 Root Not Trusted

File Traits

  • dll
  • x64

Block Information

Total Blocks: 10,809
Potentially Malicious Blocks: 32
Whitelisted Blocks: 9,124
Unknown Blocks: 1,653

Visual Map

0 0 0 0 ? ? ? 0 ? ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 ? ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? 0 ? 0 0 0 0 0 ? 0 ? 0 0 ? ? 0 0 0 ? ? ? ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 ? ? 1 ? 0 0 0 ? ? 1 ? 0 0 0 ? 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 ? 0 1 0 0 0 x 0 0 0 0 0 ? ? 0 0 ? 0 0 0 ? ? 0 ? ? 0 x ? 0 0 ? 0 0 0 ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 ? ? 0 ? ? 0 ? ? 0 ? 0 0 ? ? 0 ? ? 0 ? ? 0 ? ? ? 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 ? ? 0 0 ? 0 0 ? 0 0 ? 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 x 0 0 x 0 0 ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 ? 0 0 ? 0 0 ? 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 ? 0 0 0 0 0 ? ? 0 ? ? 0 ? ? 0 ? ? 0 ? ? 0 0 0 ? 0 ? 0 0 0 ? ? ? ? 0 0 0 0 0 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 1 1 0 0 0 0 0 0 ? 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 ? 0 ? 0 0 0 0 ? ? 0 0 1 1 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 ? 0 0 0 0 ? ? ? ? 0 ? 0 ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 ? ? 0 ? ? ? 0 0 0 ? 0 0 0 0 0 0 0 ? 1 ? 0 0 0 ? ? ? ? ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 ? 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? ? 0 ? ? ? 0 x ? ? ? 0 ? ? ? 0 ? 0 ? ? ? ? ? ? 0 ? 0 0 0 0 ? ? 0 0 ? 0 ? 0 ? ? ? 0 ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 ? 0 ? 0 ? 0 0 ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? ? 0 0 0 0 0 ? ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 ? ? ? 0 ? ? ? ? 0 0 0 0 0 ? ? ? 0 0 ? ? 0 0 ? 0 0 0 0 ? 0 0 ? ? ? 0 0 ? ? 0 0 ? ? ? 0 ? ? 0 0 1 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? 0 ? ? ? ? ? ? 0 ? 0 0 ? 0 ? 0 ? ? 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 ? 0 ? 0 ? 0 0 0 ? 0 ? ? ? 0 0 0 ? ? 0 ? ? ? ? 0 0 0 0 0 ? ? ? ? ? ? ? 0 ? 0 0 0 0 ? ? 0 0 0 ? ? ? 0 ? x 0 0 0 0 0 x 0 0 0 ? ? ? 0 0 ? ? ? 0 ? 0 ? 0 ? ? 0 0 ? ? ? 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? ? 0 0 0 0 0 ? 0 0 ? 0 0 x 0 0 0 0 ? ? 0 0 0 0 0 ? ? ? ? 0 ? 0 0 ? x ? ? 0 0 0 0 1 ? 0 0 ? ? ? 0 ? ? 0 ? 0 0 ? ? ? ? ? 0 ? 0 0 ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? 0 0 0 ? ? ? ? ? ? 0 ? 0 0 ? 0 ? 0 0 0 ? ? ? ? 0 ? ? ? ? ? 0 0 0 ? ? 0 ? 0 ? 0 ? ? ? ? ? 0 0 0 ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 ? ? ? 0 ? ? 0 0 ? ? ? ? ? ? ? ? 1 ? ? ? ? ? ? 0 0 0 1 0 0 ? ? ? 0 ? 0 ? 0 0 0 0 ? ? ? ? 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 x ? 0 0 0 ? ? 0 0 0 ? ? ? 0 ? ? ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 0 0 ? ? 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 ? ? 0 ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? ? ? 0 ? 0 ? 0 0 0 0 0 0 ? 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 ? ? 0 ? 0 ? ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? 0 0 0 0 0 1 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 ? ? ? ? ? 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 ? 0 ? ? ? ? 0 ? 0 ? 0 0 0 0 0 ? x ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 ? 0 0 ? ? 0 ? 0 0 0 0 ? 0 ? ? 0 ? ? ? 0 ? ? 0 ? 0 0 ? 1 0 0 0 0 1 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 0 0 ? 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 ? 0 0 0 0 ? ? 0 0 0 0 1 0 0 0 0 ? ? ? ? ? ? ? ? x 0 ? 0 ? 0 ? ? 0 0 ? ? 0 ? ? ? ? 0 ? 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • ntdll.dll!NtYieldExecution
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiGetDCforBitmap
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiRestoreDC
  • win32u.dll!NtGdiSaveDC
  • win32u.dll!NtGdiSelectBitmap
  • win32u.dll!NtGdiSetDIBitsToDeviceInternal
  • win32u.dll!NtUserBuildHwndList
  • win32u.dll!NtUserCallTwoParam
  • win32u.dll!NtUserCreateEmptyCursorObject
  • win32u.dll!NtUserCreateWindowEx
  • win32u.dll!NtUserDestroyWindow
  • win32u.dll!NtUserFindExistingCursorIcon
  • win32u.dll!NtUserGetAncestor
  • win32u.dll!NtUserGetClassInfoEx
  • win32u.dll!NtUserGetClassName
  • win32u.dll!NtUserGetDC
  • win32u.dll!NtUserGetGUIThreadInfo
  • win32u.dll!NtUserGetIconInfo
  • win32u.dll!NtUserGetIconSize
  • win32u.dll!NtUserGetImeInfoEx
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetObjectInformation
  • win32u.dll!NtUserGetProcessWindowStation
  • win32u.dll!NtUserGetProp
  • win32u.dll!NtUserGetThreadDesktop
  • win32u.dll!NtUserGetThreadState
  • win32u.dll!NtUserGetWindowCompositionAttribute
  • win32u.dll!NtUserIsNonClientDpiScalingEnabled
  • win32u.dll!NtUserIsTopLevelWindow
  • win32u.dll!NtUserMessageCall
  • win32u.dll!NtUserRegisterClassExWOW
  • win32u.dll!NtUserRegisterWindowMessage
  • win32u.dll!NtUserReleaseDC
  • win32u.dll!NtUserRemoveProp
  • win32u.dll!NtUserSelectPalette
  • win32u.dll!NtUserSetCursorIconData
  • win32u.dll!NtUserSetWindowFNID
  • win32u.dll!NtUserSetWindowLongPtr
  • win32u.dll!NtUserSetWindowPos
  • win32u.dll!NtUserUpdateInputContext

Trending

Most Viewed

Loading...