Threat Database Trojans Trojan.Agent.Gen.AAP

Trojan.Agent.Gen.AAP

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 1
First Seen: December 26, 2025
Last Seen: April 8, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.Gen.AAP indicates that your system has been compromised by a type of malicious software known as a Trojan. This category of threat is designed to deceive users by disguising itself as legitimate software, but in reality, it is intended to cause harm or exploit the infected system. Understanding the nature of this threat and how it operates is crucial in taking effective steps towards its removal and preventing future infections.

What Is Trojan.Agent.Gen.AAP?

Trojan.Agent.Gen.AAP is identified as a Trojan-type threat, which means it is a broad category of malware that uses deception to infect systems. The term "Trojan" originates from the Trojan Horse legend, symbolizing how these malware types disguise themselves as harmless or useful applications to gain unauthorized access to a computer system. The specifics of Trojan.Agent.Gen.AAP, such as its exact behaviors or the methods it uses to spread, can vary, but its classification as a Trojan indicates its potential to cause significant harm by stealing data, disrupting system operation, or providing unauthorized access to the system.

How Trojan.Agent.Gen.AAP Operates

Trojan.Agent.Gen.AAP, like other Trojans, is designed to operate covertly, attempting to evade detection by security software and system administrators. It may spread through various means, including but not limited to, infected software downloads, malicious email attachments, or exploits of system vulnerabilities. Once inside a system, it can execute a range of malicious activities, from data theft and espionage to using the system as a botnet node for further malicious activities. Its operation can lead to system instability, performance issues, and significant security risks.

Symptoms of Infection

Identifying a Trojan infection can be challenging due to its stealthy nature. However, several symptoms may indicate the presence of malware like Trojan.Agent.Gen.AAP. These include unexpected system crashes, slow system performance, appearance of unwanted programs or toolbars, unfamiliar network activity, and pop-ups or other signs of adware activity. Additionally, if your antivirus software is disabled without your intervention or if you notice strange or unauthorized changes to your system settings, these could also be indicators of a Trojan infection.

How to Remove Trojan.Agent.Gen.AAP

  1. Enter Safe Mode with Networking to limit the malware's ability to interfere with the removal process. This mode allows you to use the internet to download necessary removal tools while restricting the execution of most user-installed applications, including the malware.
  2. Perform a full scan of your system using a reputable anti-malware tool such as SpyHunter. Ensure the tool is updated with the latest definitions to enhance its ability to detect and remove the threat.
  3. Uninstall suspicious programs that you do not recognize or that were installed without your knowledge. Be cautious and only remove programs you are certain are malicious or unnecessary.
  4. Reset your web browsers (e.g., Chrome, Firefox, Edge) to their default settings. This step can help remove any malicious extensions or settings changes made by the Trojan.
  5. After completing the above steps, reboot your system and then perform another full scan to ensure that the malware has been completely removed and that no additional threats are present.

Conclusion

The removal of Trojan.Agent.Gen.AAP requires careful and systematic steps to ensure the malware is completely eradicated from the system. It's also crucial to adopt preventive measures to avoid future infections, including keeping your operating system and software up to date, using strong and unique passwords, being cautious with email attachments and downloads, and regularly scanning your system with reputable security software. By understanding the nature of Trojan threats and taking proactive steps in security and maintenance, you can significantly reduce the risk of your system being compromised by malware like Trojan.Agent.Gen.AAP.

Analysis Report

General information

Family Name: Trojan.Agent.Gen.AAP
Signature status: No Signature

Known Samples

MD5: c69f0d7ff441d30c14551b648286f82d
SHA1: a6a28f0b0f8aefdb16f7a59459b2e2d4eb59d12b
SHA256: D20A94B8AE092ECB15F0754A54C5EA5F1FD4F046909CD35FBFD1F9345DF30D1F
File Size: 467.97 KB, 467968 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • No Version Info
  • ntdll
  • x64

Block Information

Total Blocks: 1,763
Potentially Malicious Blocks: 38
Whitelisted Blocks: 1,519
Unknown Blocks: 206

Visual Map

0 x ? x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 1 1 ? x 0 ? 0 ? ? 0 0 ? 0 0 0 0 0 0 x 0 0 0 0 ? ? 0 ? 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 ? x ? ? ? x ? 0 0 0 0 0 0 x ? ? ? ? ? 0 0 ? x x ? ? 0 ? ? 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x 0 0 x 0 0 0 0 x ? 0 0 0 ? 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? 0 ? 0 ? 0 ? ? ? 0 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 0 ? ? ? ? 0 ? 0 ? ? x 0 ? ? ? 0 ? ? ? ? 0 ? ? ? ? 0 ? ? 0 0 ? ? ? ? 0 ? 0 0 ? 0 ? 0 0 ? 0 0 0 0 ? ? ? 0 x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 x 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 ? 0 0 ? ? ? ? ? 0 0 0 ? 0 0 0 0 ? 0 0 0 ? 0 0 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pshost.134262657344181165.8044.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\977561bde9.exe Synchronize,Write Data
c:\users\user\appdata\local\temp\__psscriptpolicytest_dj0zadje.w5o.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_w3vu13jy.kmo.ps1 Generic Write,Read Attributes
c:\users\user\downloads\a6a28f0b0f8aefdb16f7a59459b2e2d4eb59d12b_0000467968 Synchronize,Write Data
c:\users\user\downloads\a6a28f0b0f8aefdb16f7a59459b2e2d4eb59d12b_0000467968.old Synchronize,Write Data
c:\users\user\downloads\a6a28f0b0f8aefdb16f7a59459b2e2d4eb59d12b_0000467968.update Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 㺕Lǜ RegNtPreCreateKey
HKLM\software\classes\xorloader:: URL:xorloader Protocol RegNtPreCreateKey
HKLM\software\classes\xorloader::url protocol RegNtPreCreateKey
HKLM\software\classes\xorloader\shell\open\command:: "C:\ProgramData\977561bde9.exe" "%1" RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAccessCheckAndAuditAlarm
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateLocallyUniqueId
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcCreateResourceReserve
Show More
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcOpenSenderProcess
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcQueryInformationMessage
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFindAtom
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryEvent
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueueApcThreadEx2
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort

167 additional items are not displayed above.

Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserNameEx
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Other Suspicious
  • AdjustTokenPrivileges

Shell Command Execution

C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe "powershell" -WindowStyle Hidden -Command "while (Test-Path $env:TARGET) { Remove-Item -Force $env:TARGET -ErrorAction SilentlyContinue
c:\users\user\downloads\a6a28f0b0f8aefdb16f7a59459b2e2d4eb59d12b_0000467968 "c:\users\user\downloads\a6a28f0b0f8aefdb16f7a59459b2e2d4eb59d12b_0000467968"

Related Posts

Trending

Most Viewed

Loading...