Threat Database Trojans Trojan.Agent.Gen.ADZ

Trojan.Agent.Gen.ADZ

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 1
First Seen: January 7, 2026
Last Seen: March 11, 2026
OS(es) Affected: Windows

Security analysts frequently encounter threats that operate quietly in the background, compromising system integrity without drawing immediate attention. Trojan.Agent.Gen.ADZ is one such detection. Identified as a Windows PE executable, this threat lacks a valid digital signature, which is a common characteristic of unauthorized or malicious software. Because it does not present a verified publisher, users must rely on robust security practices and reputable anti-malware tools to detect and mitigate the risks associated with this generic Trojan detection.

What Is Trojan.Agent.Gen.ADZ?

Trojan.Agent.Gen.ADZ is a detection name used to classify a specific Windows PE executable that exhibits behavior consistent with Trojan horses. A Windows PE (Portable Executable) file is a standard format for executables, DLLs, and system components within the Windows operating system. However, in this context, the file operates outside its intended boundaries. The absence of a digital signature is a critical factor in its identification. Legitimate software developers typically sign their executables to verify the publisher's identity and ensure the file has not been tampered with. Because this threat carries no signature, operating systems and security suites cannot verify its origin, inherently categorizing it as untrusted and potentially harmful.

How Trojan.Agent.Gen.ADZ Operates

As a generic Trojan detection, Trojan.Agent.Gen.ADZ generally functions by disguising itself as a benign application or hiding within legitimate system processes to avoid detection. Once executed, the Windows PE file may attempt to establish persistence on the host machine, allowing it to run continuously across system reboots. Trojans of this nature often modify system configurations, create unauthorized registry entries, or inject code into running processes. Lacking a valid signature, the executable bypasses standard trust verification protocols, though modern operating systems may still flag it during execution attempts. The primary goal of such threats is typically to facilitate unauthorized access, gather system information, or create a backdoor for additional payloads.

Symptoms of Infection

Identifying a Trojan infection can be challenging, as these threats are designed to operate stealthily. However, users may observe several general symptoms indicating the presence of Trojan.Agent.Gen.ADZ:

  • Unexpected system slowdowns or a noticeable decrease in overall performance.
  • Unrecognized processes running in the Windows Task Manager.
  • Unexplained network activity, suggesting the threat is communicating with external servers.
  • System crashes, freezes, or programs failing to launch correctly.
  • Security software being disabled or failing to update properly.

How to Remove Trojan.Agent.Gen.ADZ

Removing Trojan.Agent.Gen.ADZ requires a systematic approach to ensure all components of the threat are eliminated. Follow these steps to restore your system's security:

  1. Boot your computer into Safe Mode with Networking to prevent the threat from loading automatically and to allow internet access for security tools.
  2. Run a full system scan with a reputable anti-malware tool such as SpyHunter to detect and quarantine the malicious executable.
  3. Uninstall any suspicious or unrecognized programs from the Windows Control Panel that may be associated with the threat.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any unauthorized extensions or modified configurations.
  5. Reboot your computer normally and run a second full scan to ensure the threat has been completely removed.

Conclusion

Trojan.Agent.Gen.ADZ represents a significant security risk due to its nature as an unsigned Windows PE executable. The lack of a digital signature underscores the importance of verifying software origins before execution. By understanding how this threat operates and adhering to a strict removal protocol, users can effectively mitigate the risks posed by this generic Trojan. Maintaining updated anti-malware defenses and exercising caution with unverified files remain the most effective strategies against such threats.

Analysis Report

General information

Family Name: Trojan.Agent.Gen.ADZ
Signature status: No Signature

Known Samples

MD5: 2fdea1ac05f9a5362d305999ae4f290b
SHA1: 8596e2a23e293fb6c56588f0da2f907cfece653b
SHA256: A5240F1A94877CE9CFD915238F40AD7366D8CCCA1A2A1CCB85317BC8B5DB79A3
File Size: 416.77 KB, 416768 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • GetConsoleWindow
  • No Version Info
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 1,390
Potentially Malicious Blocks: 704
Whitelisted Blocks: 686
Unknown Blocks: 0

Visual Map

x x x 0 x 0 0 x x x x x x 1 0 x 0 x x x x 1 x 0 x x x 0 0 0 0 0 0 x x x 0 x x x x x 0 0 0 x x x x 0 0 x x x x 1 x 0 x 0 0 0 x x x x x x x x x x x x x x x x x x 0 x 1 x 1 x x x x x x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 x 0 x x 0 x x x 0 0 x x x x 0 x x x 0 x 0 x x x x x x x 0 0 x x 0 0 x x x x x 0 x 0 0 x x x x x 1 x x 0 x 0 0 0 0 0 0 0 x x x 0 x x x x x x 0 x x x x x 0 x x x 0 x 0 x 0 x x 0 x x 0 x x 0 0 x 0 x x x 0 0 x 0 x x x x 0 x x x x x 0 x x 0 x x x x 0 x x x 0 0 x x x x 0 x x x x x x x x 0 0 0 x x x 0 0 x x x x x x x x 0 0 x x 0 x x x x x 0 x x x 0 x x 0 0 0 x x x x x 0 x x 0 x x x x x x x x x 0 x x x x x 0 0 x x x x x 0 x 0 0 x x x 0 x x x x 0 0 x x 0 x 0 x 0 x x 0 x 0 x x x x x x x 0 x x x 0 x x x 0 0 x x 0 x x x x 0 x x x x x x x 0 x x 0 x x 0 0 x 0 x x 0 x x x x 0 x x x x 0 1 x x x x x x 0 x 0 x 0 x x x x x x 0 x x x x x x x 0 x x x x 0 x 0 x x x x x x x x 0 0 x x x x x x x x 0 x x 0 x x x 0 x 0 x x x x x x 0 x x 0 x x x 0 x 0 x 0 x x 0 x x x x 0 x x x x 0 x x x x x 0 0 x x x x 0 x x x x 0 0 x x 0 x x x x x 0 x x 0 x x x 0 x x 0 x x x 0 x x 0 x x x x x x x 0 x x x 0 x x x x x 0 x 0 x x x 0 x x x 0 x x x x x 0 x 0 x x x 0 x x x 0 x x x x 0 x 0 x x x 0 0 x x x 0 x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x 0 x 0 x x x x x x x 0 x x x x x x 0 0 x x x 0 0 x x x 0 x x x x x x 0 0 x x x x 0 0 0 x x 0 0 x x x x 0 x x 0 0 x x x x 0 x x 0 0 x x x x 0 x x x 0 x x x x 0 0 x x x x 0 0 0 x x 0 0 x x x x 0 0 0 x x 0 0 x x x x 0 x x 0 0 x x x x 0 x 0 x 0 x x x x 0 0 x x x x x 0 0 x x x x x 0 0 x x x x x 0 0 x x x x x 0 x x x 0 x x x x 0 0 x x x x x 0 0 x x x x x 0 0 x x x x x 0 0 x x x x x 0 x 0 x 0 x x x x 0 0 x x x 0 0 x x 0 0 x x x x x 0 0 x x x x x 0 0 x x x x x 0 x x x 0 x x x x 0 0 x x x x x 0 0 x x x x x 0 0 x x x x x 0 0 x x x x x 0 x 0 x 0 x x x x 0 x x 0 x x x x x 0 x x 0 x x x 0 x 0 x 0 0 0 0 x x x x x x x 0 x x x 0 0 x x x 0 x x x x x 0 x x 0 x 0 x 0 x x 0 x x 0 x x x x x 0 x x x x 0 1 0 1 0 1 1 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 1 1 0 0 0 1 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Files Modified

File Attributes
c:\windows\wini92uh3.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\wini92uh3.exe Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old122e4*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old12352*1\??\C:\P RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 讵ﱋ˗ǝ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 亢ﱐ˗ǝ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
Show More
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
Network Winsock2
  • WSAStartup
Anti Debug
  • IsDebuggerPresent
  • OutputDebugString
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Service Control
  • OpenSCManager
  • StartService
User Data Access
  • GetUserObjectInformation
Process Terminate
  • TerminateProcess

Shell Command Execution

"C:\WINDOWS\wini92uh3.exe" -install
cmd.exe /C timeout /t 3 /nobreak > Nul & Del /f /q "c:\users\user\downloads\8596e2a23e293fb6c56588f0da2f907cfece653b_0000416768"
C:\WINDOWS\system32\timeout.exe timeout /t 3 /nobreak

Related Posts

Trending

Most Viewed

Loading...