Threat Database Trojans Trojan.Agent.DFDE

Trojan.Agent.DFDE

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 11,657
Threat Level: 80 % (High)
Infected Computers: 226
First Seen: December 3, 2024
Last Seen: May 6, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.DFDE indicates that your system has been compromised by a potentially malicious program. This type of threat is designed to infiltrate your computer without your knowledge or consent, and it can cause a range of problems, from slowing down your system to stealing sensitive information. In this report, we will provide an overview of what Trojan.Agent.DFDE is, how it operates, and the steps you can take to remove it from your system.

What Is Trojan.Agent.DFDE?

Trojan.Agent.DFDE is a type of Trojan horse malware, which is a broad category of malicious software that is designed to disguise itself as a legitimate program. The name "Trojan.Agent.DFDE" suggests that it is a type of agent-based malware, which is designed to interact with other systems or servers to carry out its malicious activities. However, without more specific information, it is difficult to determine the exact nature and purpose of this threat.

How Trojan.Agent.DFDE Operates

Like other types of Trojan horse malware, Trojan.Agent.DFDE is likely designed to operate in stealth mode, avoiding detection by security software and system administrators. It may use various techniques to evade detection, such as code obfuscation, encryption, or exploiting vulnerabilities in system software. Once installed on a system, Trojan.Agent.DFDE may communicate with its creators or other systems to receive instructions, transmit stolen data, or download additional malware components.

Symptoms of Infection

Systems infected with Trojan.Agent.DFDE may exhibit a range of symptoms, including slow system performance, unexpected crashes or freezes, and unusual network activity. You may also notice that your system is behaving erratically, such as displaying unusual error messages or pop-ups, or that your personal data is being transmitted without your consent. However, some systems may not display any noticeable symptoms at all, which is why regular system scans and monitoring are essential for detecting and removing malware.

How to Remove Trojan.Agent.DFDE

To remove Trojan.Agent.DFDE from your system, follow these steps:

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and run a full system scan to detect and remove all instances of Trojan.Agent.DFDE.
  3. Uninstall any suspicious programs or applications that may be related to the malware infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and run another full system scan to ensure that all instances of Trojan.Agent.DFDE have been removed.

Conclusion

Removing Trojan.Agent.DFDE from your system requires careful attention to detail and a thorough understanding of the malware removal process. By following the steps outlined in this report, you can help to ensure that your system is free from this potentially malicious program and that your personal data is protected. Remember to always be cautious when downloading and installing software, and to regularly scan your system for malware to prevent future infections.

Analysis Report

General information

Family Name: Trojan.Agent.DFDE
Signature status: No Signature

Known Samples

MD5: 11d6f093b4afe4a02fc5c4665d11f807
SHA1: d2c5efa922967144aa7367ef0eaded26b9105e31
SHA256: 51EDC22724C2A686F740D8B1FDCA29F61BEA5B4378FE042980CEEE5D401F8530
File Size: 111.05 KB, 111049 bytes
MD5: 119350e4d83b0cc85bdab8b6cec168f4
SHA1: 07c17d3282af617a53d1e97c7963210fb93ea730
SHA256: 9555D97F8079A7B61881D478081097A2CB2B6C4B2DC7EF06B42FD3522577C5D3
File Size: 2.23 MB, 2225828 bytes
MD5: ab162879fabf5213a1d21c47a319d2cc
SHA1: 9b01547719891ebbe773a9d97473277e64187c1b
SHA256: 7A9F39AEE2DE7DD59DA9484F7D25A6B9F9225426ED27ADFF7796388A2C46E537
File Size: 2.23 MB, 2225340 bytes
MD5: 3831fb347d7e092efb66d9e6d33ef3cc
SHA1: 9e84c2f2a1378cc0fe36a1ab3588a85fc4f08726
SHA256: 0D86F137943B32C91C06427F32F40E5DCC036C2F5ECDB59F66D04BEE8949A200
File Size: 2.21 MB, 2212409 bytes
MD5: ff0a3860ae893628fc9852835ad4c118
SHA1: db096f68567b157b0ef6a1d28feb1fe38f9f377f
SHA256: 51C863ADCA0AC2847D6C56166CC33ECB36639454D06343FD041AB2D000475277
File Size: 2.22 MB, 2222104 bytes
Show More
MD5: 287fd707268be5b65fe204d71fcaec3d
SHA1: 492051072607fbeccda8e5b0e11543c21b4b11b0
SHA256: 0973A309D22C86BAD662366CDC7DA9D935536B3BEF2C1351F5838AC083BA3AEE
File Size: 65.81 KB, 65807 bytes
MD5: e4e5040cd4f3756748ee45be1fb8d946
SHA1: 1e1ecfcccc481e2c8eda351cd76109a93dbf52c4
SHA256: 79FC11B3538287F1CCE486743891661A142EAF8EB3DD7E7F97993008BD62C909
File Size: 101.89 KB, 101886 bytes
MD5: 0c486ec8601cefe5d83ec991c90ac99c
SHA1: bf7f5c1d4055ab678ff7f692f37b82489bfdd4b1
SHA256: 8D92B6CBBFDB0B5E2736F4299E38E3BCCB30B6769EA58B4A1809B45C23F4C85A
File Size: 771.07 KB, 771072 bytes
MD5: 93d0db88db9d2305ddba8017b299e0f1
SHA1: a785fcc2d5a4c9736621c6f75436f2114f017b05
SHA256: 7DAFED647EC8CBF5F43AF1832AE8E9FECD9169CC9466CCB2DE5E98CA9A6221F7
File Size: 2.22 MB, 2222104 bytes
MD5: ca322d1293404e760677433e249bd747
SHA1: b53c9287227d8c43915fad9dc2d2a0f9573371d0
SHA256: 4C666488FB473B35B36ED6D3383FB74FC8E078A3230C4314E218061B6909A0C4
File Size: 89.50 KB, 89503 bytes
MD5: b533262b3d85b4f2e92f59c45da3e7ed
SHA1: ce2731155e893280ab53eb58e47a2f4e79150da9
SHA256: 16B74AFC729EFCABF7FF2FC71984BFA9CB5F4A4BCE9967E7AB5BC0EBCC30E518
File Size: 992.26 KB, 992256 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name SegaTools IDZHook
File Version
  • 1.0.0.39
  • 1.0.0.38
  • 1.0.0.35
Legal Copyright ©2020 djhackers & TeknoGods
Original Filename idzhook.dll
Product Name SegaTools IDZHook
Product Version
  • 1.0.0.39
  • 1.0.0.38
  • 1.0.0.35

File Traits

  • big overlay
  • dll
  • x64

Block Information

Total Blocks: 1,518
Potentially Malicious Blocks: 2
Whitelisted Blocks: 896
Unknown Blocks: 620

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 0 ? ? 0 ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? 0 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 ? ? ? ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? 0 ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.UFH
  • Agent.XVI
  • Metasploit.X
  • ReverseShell.UA
  • Trojan.Kryptik.Gen.BX

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 h +�Bx1HO9�@V�@��g��y�^�P���������������� [�m���'��$�`�V��� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 沐 ⬉ʾ䈛x䠱O噀ñ傄ë횎ǜɼ鶝’꾢ʊ閾ʴ淃⟋ʪߙĤ鈄ĞꩠŖÉ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
Show More
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueryWnfStateNameInformation
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUpdateWnfStateData
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtGdiAnyLinkedFonts
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiComputeXformCoefficients
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateRectRgn
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiDoPalette
  • win32u.dll!NtGdiExcludeClipRect
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiExtSelectClipRgn
  • win32u.dll!NtGdiExtTextOutW
  • win32u.dll!NtGdiFontIsLinked
  • win32u.dll!NtGdiGetCharABCWidthsW
  • win32u.dll!NtGdiGetDCDword
  • win32u.dll!NtGdiGetDCforBitmap
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiGetDIBitsInternal

92 additional items are not displayed above.

Trending

Most Viewed

Loading...