Threat Database Trojans Trojan.Agent.DRZ

Trojan.Agent.DRZ

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 11,735
Threat Level: 80 % (High)
Infected Computers: 26
First Seen: July 9, 2025
Last Seen: July 4, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.DRZ on your system indicates a potential security threat that requires immediate attention. This type of threat is generally classified as a Trojan, which is a broad category of malware that can perform a variety of malicious actions on an infected computer. Trojans are often designed to allow unauthorized access to a computer system, and they can be used to steal sensitive information, disrupt system operation, or provide a conduit for additional malware infections.

What Is Trojan.Agent.DRZ?

Trojan.Agent.DRZ is a type of malware that falls under the Trojan category. The specifics of its operation and the exact nature of its malicious activities can vary, but like other Trojans, it is designed to compromise the security and integrity of a computer system. Malware of this type can be spread through various means, including but not limited to, downloads from untrusted sources, email attachments, and exploits of software vulnerabilities.

How Trojan.Agent.DRZ Operates

The operational details of Trojan.Agent.DRZ are not explicitly defined without specific analysis, but Trojans in general operate by exploiting vulnerabilities in software or human behavior to gain unauthorized access to a system. Once inside, they can create backdoors for remote access, steal personal data, install additional malware, or disrupt system operations. The ability of a Trojan to remain hidden and the variety of its potential actions make it a significant threat to computer security.

Symptoms of Infection

Symptoms of a Trojan infection can be subtle and may not always be immediately apparent. Common indicators include unusual system behavior, such as slowed performance, frequent crashes, or the appearance of unfamiliar programs or icons. Additionally, users may notice unauthorized changes to their system settings, unexpected pop-ups, or unusual network activity. However, some Trojans are designed to operate stealthily, making them difficult to detect without the aid of security software.

How to Remove Trojan.Agent.DRZ

  1. Boot your computer in Safe Mode with Networking to limit the malware's ability to interfere with the removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove the Trojan and any associated malware.
  3. Uninstall any recently installed programs that you do not recognize or that were installed around the time the malware was detected.
  4. Reset your web browsers (e.g., Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all remnants of the malware have been removed.

Conclusion

The removal of Trojan.Agent.DRZ requires a careful and systematic approach to ensure that all components of the malware are eliminated from the infected system. By following the steps outlined above and maintaining vigilant security practices, such as keeping software up to date, using strong antivirus protection, and being cautious with downloads and email attachments, you can help protect your computer from future malware infections. Remember, prevention and prompt action are key to minimizing the impact of malware threats.

Analysis Report

General information

Family Name: Trojan.Agent.DRZ
Signature status: No Signature

Known Samples

MD5: a5f8a507818026b6bfa1fdd921a49de9
SHA1: d428d4317dfbc3df1b1cc83d685ae5f77a80575a
SHA256: 223363D61E8BBE7DD18D81263D01F06E7749786708DEBFC9AB250638E594D0E5
File Size: 739.33 KB, 739328 bytes
MD5: 51160d9a48d622834dd8617d37a0f19c
SHA1: 3a04ff2513595a647c8624e7eeaff42cad96be38
SHA256: 9BCFC0FE6071180E05BBE2A309F41B71B9998AC73CCE79E811139CE11F0874CB
File Size: 739.33 KB, 739328 bytes
MD5: f8276d4ff4da6606784e9050f8d87344
SHA1: 4a725a02e4d0e8f19bd95862c7224c23ee3342db
SHA256: 4786D88D9462AED6DB4F7CA1F739CFA44DB8A03357FA8528F3E8294DC945751F
File Size: 739.33 KB, 739328 bytes
MD5: f881b47cd1c126bd8160992b5c30b6ac
SHA1: d9318d426e551c9c29d0e186638f5437f3054172
SHA256: AB4687B09AB693BF7ACF68231B449B1E8CA819D1F2EEEE436BAB245491B746DB
File Size: 438.78 KB, 438784 bytes
MD5: 82b80da3bea50aee7b639e1683e7ea03
SHA1: ffdc477aa64826060284d7fe58bb58e1e352d478
SHA256: 6C11DFBBDE697E0987BFF2A72D14B47EC89891A1DF3C650C886D42D5A9944D08
File Size: 740.86 KB, 740864 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • HighEntropy
  • imgui
  • No Version Info
  • packed
  • VirtualQueryEx
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 1,389
Potentially Malicious Blocks: 195
Whitelisted Blocks: 1,177
Unknown Blocks: 17

Visual Map

0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 ? x x x 0 0 0 0 x x 1 0 x 0 0 0 x 0 0 x 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 ? x ? x 0 x 0 0 0 0 x 0 0 x x 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 x x 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 x x x x x x x 0 0 0 0 0 x 0 x 0 x 0 0 0 x 0 x 0 0 0 0 1 0 x 0 x 0 x 0 0 0 0 0 0 0 x x x 0 0 0 0 0 x 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 x 0 0 1 0 0 1 0 0 0 0 1 0 0 1 0 0 1 0 0 1 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 x x 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 ? 1 0 0 1 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x x x 0 x 0 0 x 0 0 x x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x x 0 0 0 0 x x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 x 0 0 0 0 0 x 0 ? ? 0 0 x x 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 x x 0 x 0 0 0 x x 0 0 0 0 x 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x x x x x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 1 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x x 0 x 0 0 0 x 0 0 1 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 0 x 0 0 0 0 x x x x x x 0 x 0 x x 0 x x x 0 0 0 0 x x 0 x 0 0 0 0 x x 0 x 0 0 0 0 x x 0 x 0 0 0 0 x x 0 x 0 0 0 x x 0 0 0 x 0 0 0 x x 0 0 x x 0 0 0 0 x x 0 0 0 0 0 0 0 0 ? 0 0 0 x 0 0 0 0 0 0 0 ? 0 0 x 0 0 0 0 0 0 0 x 0 ? 0 x x 0 x x x 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 x x 0 0 0 0 0 0 x 0 ? 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.DRZ
  • CsgoInjector.RC

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe �Y��K� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 胬哳厃ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 矇✉塂ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 섌엷煉ǜ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
Network Winsock2
  • WSAStartup
Network Winsock
  • closesocket
  • connect
  • send
  • setsockopt
  • socket

Related Posts

Trending

Most Viewed

Loading...