Threat Database Trojans Trojan.Agent.FDGD

Trojan.Agent.FDGD

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 375
Threat Level: 80 % (High)
Infected Computers: 6,599
First Seen: March 12, 2025
Last Seen: July 20, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.FDGD on your system indicates a potential security threat. This detection name suggests a type of Trojan horse malware, which is a broad category of threats that can have various effects on infected systems. Trojan horses are known for their ability to disguise themselves as legitimate programs, making them difficult to detect without proper security software.

What Is Trojan.Agent.FDGD?

Trojan.Agent.FDGD, as indicated by its name, falls under the Trojan category of malware. Trojans are malicious programs that can allow unauthorized access to a computer, leading to a range of harmful activities such as data theft, installation of additional malware, and disruption of system operation. The specific capabilities and intentions of Trojan.Agent.FDGD can vary, but its classification as a Trojan suggests it could be used for malicious purposes such as spying, stealing sensitive information, or using the infected computer for malicious activities.

How Trojan.Agent.FDGD Operates

The operation of Trojan.Agent.FDGD, like other Trojans, typically involves exploiting vulnerabilities in software or tricking users into executing the malware. Once installed, it can operate in various ways, potentially including communicating with command and control servers to receive instructions, downloading and installing other malware, or exfiltrating sensitive data from the infected system. The exact mechanisms of operation can depend on the specific goals of the malware authors and the design of the Trojan.

Symptoms of Infection

Symptoms of a Trojan infection can be subtle and may not always be immediately noticeable. Common indicators include unusual system behavior, such as unexpected pop-ups, slow system performance, or frequent crashes. Additionally, users might notice unfamiliar programs or toolbars in their browser, changes in system settings, or increased network activity. However, some Trojans are designed to operate stealthily, making them harder to detect without the use of antivirus software.

How to Remove Trojan.Agent.FDGD

  1. Boot into Safe Mode with Networking: This will help prevent the malware from loading and make it easier to remove. Safe Mode starts Windows in a basic state, using a limited set of files and drivers, which can help you troubleshoot problems.
  2. Perform a Full Scan with a Reputable Tool: Utilize a reputable anti-malware tool, such as SpyHunter, to scan your system thoroughly. Ensure the tool is updated with the latest definitions to improve the chances of detecting and removing the Trojan.
  3. Uninstall Suspicious Programs: Go through the list of installed programs on your system and uninstall any that you do not recognize or that were installed around the time the infection was detected.
  4. Reset Your Browser Settings: If your browser has been affected, resetting it to its default settings can help remove any malicious extensions or settings changes. This applies to browsers like Chrome, Firefox, and Edge.
  5. Reboot and Re-scan: After taking the above steps, restart your computer and perform another full scan with your anti-malware tool to ensure that the Trojan has been completely removed and no additional threats are present.

Conclusion

The detection and removal of Trojan.Agent.FDGD require careful attention to system security and the use of reputable anti-malware tools. Preventing future infections involves maintaining up-to-date software, being cautious with email attachments and downloads, and regularly scanning your system for threats. By understanding the nature of Trojan horse malware and taking proactive steps, you can protect your system and data from potential harm.

Analysis Report

General information

Family Name: Trojan.Agent.FDGD
Signature status: Hash Mismatch

Known Samples

MD5: bb5bd5f25cc1c859b994342d2a702612
SHA1: c4f6e8655a3846f4be959be62c64972deb54a905
SHA256: 623BEF443B83FC482CFEE52EEB9B4974225AB957229D467DB69C4E2AE82BE76B
File Size: 2.60 MB, 2600960 bytes
MD5: 6dc39e86e76229a2416ed9b475068e50
SHA1: 8b8ba14f476e467d03644116b034ada5a21c69d9
SHA256: 8CD923D136C3C64F0427FA488593D39768620BFA50509BDA47BE793F4C58C8BE
File Size: 8.21 MB, 8209920 bytes
MD5: f9b8ad5d99f7e523d7004ac46083a064
SHA1: 38f95ec15e313cd967ab8b90897ffcdc66a8de2e
SHA256: 42723D19C781387EEF2D5079E951D553C19EBF9785B9B62F1F525D2220F481D9
File Size: 7.64 MB, 7638064 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Adobe Inc.
  • Microsoft Corporation
File Description
  • Adobe Installer
  • Win32 Cabinet Self-Extractor
File Version
  • 11.00.22000.1 (WinBuild.160101.0800)
  • 5.3.1.470
Internal Name
  • Adobe Installer
  • Wextract
Legal Copyright
  • © 2020 Adobe. All rights reserved.
  • © Microsoft Corporation. All rights reserved.
Original Filename
  • Adobe Installer
  • WEXTRACT.EXE .MUI
Product Name
  • Adobe Installer
  • Internet Explorer
Product Version
  • 11.00.22000.1
  • 5.3.1.470

Digital Signatures

Signer Root Status
Adobe Inc. DigiCert EV Code Signing CA (SHA2) Hash Mismatch

File Traits

  • 2+ executable sections
  • CryptUnprotectData
  • GetConsoleWindow
  • HighEntropy
  • Installer Version
  • x86

Block Information

Total Blocks: 9,321
Potentially Malicious Blocks: 2,013
Whitelisted Blocks: 7,302
Unknown Blocks: 6

Visual Map

x x x x x x 0 0 x 0 0 x x 0 0 x x 0 0 x x x 0 0 x 0 0 x x 0 x 0 x x 0 0 0 0 0 0 x 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x x x 0 x x 0 0 0 x x x x x x x x 0 x 0 x x 0 ? ? ? ? ? x x x x x x 0 0 0 x x x x x 0 0 0 x 0 x x 0 x x x x x 0 x x x 0 x 0 x 0 x x x x x x 0 x 0 x x x 0 0 0 x x 0 x 0 x 0 x x x x 0 x x 0 x x 0 0 x x x x x x x x 0 x x x x x x x x x x x x x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 x 0 0 0 0 0 0 0 x x 0 x x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 x x 0 0 0 x 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 x x x 0 0 x x 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x x x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 x x 0 0 x x x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 x x 0 x x x x x 0 0 0 0 0 0 0 0 0 x x x 0 x x 0 0 x x 0 x 0 x 0 0 0 0 0 x x 0 x x 0 x x x 0 0 0 0 0 0 0 x 0 x x 0 0 0 x 0 x x x 0 x 0 x 0 x x x 0 0 0 0 x 0 0 0 0 0 0 x x x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 x x x 0 x 0 0 0 0 0 0 x 0 0 0 0 x 0 x 0 ? x x 0 x 0 x 0 x x x x x 0 x 0 x 0 x x 0 0 0 x x 0 x x x 0 0 0 x 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x x x x x 0 0 0 x x x 0 0 0 x 0 0 0 x 0 x 0 x 0 x 0 x x x x x 0 0 0 0 x 0 x 0 x x x 0 x x x 0 x x 0 x 0 x 0 0 0 x 0 0 0 0 0 0 x 0 0 x 0 0 x 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 x x 0 x 0 x x x x x x x x 0 0 x x x x x x 0 x x x x 0 x x x 0 x 0 x x x x 0 0 0 x x 0 x 0 x 0 0 x 0 0 x 0 0 x 0 x 0 x x x x 0 x 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 x 0 x 0 0 0 x 0 0 0 0 x 0 0 0 x 0 0 0 0 0 x 0 0 0 0 x 0 0 x 0 x 0 0 x 0 0 x 0 x x x x 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x 0 x x x 0 0 0 0 0 0 x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 x 0 0 x x 0 0 0 0 0 0 0 x x x 0 x 0 0 0 x x x 0 x x x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 x 0 x x x x 0 x x x 0 x 0 x x 0 0 x 0 x 0 x 0 x x 0 x x x x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 x x x x x 0 x 0 x 0 x 0 x 0 x 0 x 0 0 x x x x x 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x 0 0 0 x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 x x x x x x x x x x 0 0 x x x x x 0 0 0 0 0 x x 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x 0 x x 0 0 0 x 0 0 x 0 x 0 x 0 0 x 0 0 x x x x x x x x 0 0 0 x x x x x x 0 0 x 0 0 x 0 x 0 x x x 0 x x x x x x 0 x x 0 x 0 x 0 x x 0 0 0 0 0 x 0 x 0 0 x 0 0 x 0 0 0 0 x x x x x x x x x x x x 0 x x x x x x 0 0 0 0 x x 0 x x x x 0 x 0 x 0 x x x x x 0 x x x 0 0 x x x x x 0 0 0 x 0 0 x 0 x x x x 0 0 0 0 x 0 0 x 0 0 0 x x x x 0 0 x x x x x x 0 0 x x x x 0 x 0 0 x x 0 x x x 0 0 0 0 x 0 0 x 0 0 0 x x 0 x 0 x 0 x 0 x 0 x 0 0 0 x 0 x 0 0 x 0 x 0 x 0 x 0 x 0 0 x x x 0 0 0 0 0 0 x 0 0 0 x x x x x 0 x x x x x 0 0 x x 0 x 0 x x x 0 x 0 x 0 x x x x x 0 0 x 0 0 x 0 x 0 0 0 x x x 0 0 0 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x x 0 0 x 0 0 0 x x x x 0 0 x x 0 x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 x 0 x 0 0 x x 0 x 0 0 0 0 0 x 0 x 0 0 0 0 0 x 0 x x x 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 x x 0 x x x x 0 0 x x 0 x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 x x 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.ENA
  • Agent.FDGD

Files Modified

File Attributes
c:\ibinstaller_98220.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\creativecloud\acc\adobedownload\hdinstaller.log Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\adobe_1.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\adobe_1.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\adobe_1.exe_deleted_ Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\set-up.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\set-up.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\set-up.exe_deleted_ Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\tmp4351$.tmp Generic Write,Read Attributes,Delete
c:\users\user\appdata\local\temp\nsne851.tmp Synchronize,Write Attributes
Show More
c:\users\user\appdata\local\temp\nsne851.tmp\installer.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsne851.tmp\installer.exe_deleted_ Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsne851.tmp\nsisdl.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsne851.tmp\nsisdl.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsne851.tmp\setup.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsne851.tmp\setup.exe_deleted_ Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows\currentversion\runonce::wextract_cleanup0 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Jflawtud\AppData\Local\Temp\IXP000.TMP\" RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old122e4*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old12352*1\??\C:\P RegNtPreCreateKey
HKCU\software\microsoft\internet explorer\main\featurecontrol\feature_browser_emulation::set-up.exe RegNtPreCreateKey
HKCU\software\microsoft\internet explorer\main\featurecontrol\feature_browser_emulation::8b8ba14f476e467d03644116b034ada5a21c69d9_0008209920 RegNtPreCreateKey
HKCU\software\microsoft\internet explorer\main\featurecontrol\feature_browser_emulation::38f95ec15e313cd967ab8b90897ffcdc66a8de2e_0007638064 RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
Show More
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Network Winsock2
  • WSAStartup
Network Winsock
  • closesocket
  • connect
  • gethostbyname
  • inet_addr
  • send
  • socket

Shell Command Execution

C:\Users\Jflawtud\AppData\Local\Temp\IXP000.TMP\Adobe_1.exe
"\IBInstaller_98220.exe" /VERYSILENT /PASSWORD=kSWIzY9AFOirvP3TueIs98220 -token mtn1co3fo4gs5vwq -subid 1878
"C:\Users\Jflawtud\AppData\Local\Temp\nsnE851.tmp\setup.exe" 991878
"C:\Users\Jflawtud\AppData\Local\Temp\nsnE851.tmp\installer.exe" /qn CAMPAIGN="1878"
C:\Users\Jflawtud\AppData\Local\Temp\IXP000.TMP\Set-up.exe

Trending

Most Viewed

Loading...