Threat Database Trojans Trojan.Agent.Gen.BFU

Trojan.Agent.Gen.BFU

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 17,460
Threat Level: 80 % (High)
Infected Computers: 30
First Seen: March 17, 2026
Last Seen: June 22, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.Gen.BFU indicates that your system has been compromised by a potentially malicious threat. This type of threat is commonly referred to as a Trojan, which is a broad category of malware that can perform a variety of functions, including data theft, system compromise, and unauthorized access. It is essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.

What Is Trojan.Agent.Gen.BFU?

Trojan.Agent.Gen.BFU is a generic detection name that indicates the presence of a Trojan-type threat. The term "Trojan" refers to a type of malware that disguises itself as a legitimate program or file, allowing it to bypass security measures and gain unauthorized access to a system. The ".Gen" suffix suggests that this threat is a generic or non-specific variant, which can make it more challenging to detect and remove.

How Trojan.Agent.Gen.BFU Operates

Trojan-type threats, including Trojan.Agent.Gen.BFU, typically operate by exploiting vulnerabilities in software or human behavior. They can be spread through various means, such as infected email attachments, compromised websites, or infected software downloads. Once inside a system, these threats can perform a range of malicious activities, including data theft, system compromise, and unauthorized access. They can also create backdoors, allowing attackers to remotely access and control the infected system.

Symptoms of Infection

Systems infected with Trojan.Agent.Gen.BFU may exhibit a range of symptoms, including slow system performance, frequent crashes, and unexpected behavior. Users may also notice unusual network activity, such as unexpected connections or data transfers. In some cases, the threat may attempt to communicate with its command and control servers, which can lead to further malicious activity. It is essential to be aware of these symptoms and take immediate action if they are observed.

  • Slow system performance or frequent crashes
  • Unusual network activity or unexpected connections
  • Unexpected behavior or system changes
  • Data loss or unauthorized access

How to Remove Trojan.Agent.Gen.BFU

  1. Boot your system in Safe Mode with Networking to prevent the threat from loading and to allow for internet access.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove the threat.
  3. Uninstall any suspicious programs or applications that may be related to the threat.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan to ensure that the threat has been completely removed.

Conclusion

The detection of Trojan.Agent.Gen.BFU is a serious issue that requires immediate attention. By understanding the nature of this threat and taking the necessary steps to remove it, you can help protect your system and prevent further damage. It is essential to remain vigilant and take proactive measures to prevent future infections, including keeping your software up-to-date, using strong antivirus protection, and being cautious when interacting with email attachments or downloads from unknown sources.

Analysis Report

General information

Family Name: Trojan.Agent.Gen.BFU
Signature status: Self Signed

Known Samples

MD5: 3d05a258d959cd2dfb7d563b0832d450
SHA1: 5f7ab26eaeac3f592be6df60b6818d643e2f380f
SHA256: 44D3F87A6F9DB7CCAF3351B780003CF037D0E0812AAEA02344AAB5BD60D802C3
File Size: 248.32 KB, 248320 bytes
MD5: d989f9bf3ac9328b1bc8fe0c304f868d
SHA1: d5d3b9664575adeff849f0529802a45d167ae029
SHA256: 174C7AAC21AF4D20555A0E489BD824E823893F1961C0824998BF011D494085E2
File Size: 255.41 KB, 255408 bytes
MD5: 802860f6e42af5d56e973fd32f0a7438
SHA1: 548d78dfd386ae9c7ccebb4e725d94c1f963e381
SHA256: 19B9E7B4EEEEB710615FD5793047F6737756CF56B3C6375D573664FFEACAC694
File Size: 255.44 KB, 255440 bytes
MD5: b027dd58602777dc7c60803113bcac06
SHA1: 57afc0e6902693086356405d02bb974745ef02f0
SHA256: 3667927752C68053635AE6F85BFF116851A0CC4E0393DAD9DB388FB7CD4F9A9A
File Size: 255.42 KB, 255424 bytes
MD5: edb01010ae80ac867d7efe7077db3bbf
SHA1: 6c93d116fee4ba5dbdd0c85bf50dff78cfdebca2
SHA256: DCBFFBF636B79143AD34BF928FC833C1CADD29DAD5794773D1AE122AEC6D04BF
File Size: 255.42 KB, 255416 bytes
Show More
MD5: 5bcaf4b54d77c8ba59c506e418b8630a
SHA1: 9228fc26dcf9470a7d38b45da25eb90dd713ccfe
SHA256: 5871283E0A4508990EC6C657F26F601D830ED8765C67B44AE64B72869A23A7BF
File Size: 255.40 KB, 255400 bytes
MD5: 591a1870c366b677629e7e8bd12963a0
SHA1: ddbd803119c36a42be252db3b13c492b8a4d8469
SHA256: 20BD8DF3E41E74C15565D4E005C7DE3537BF722A48C81FD184237C4F89C74EAE
File Size: 255.42 KB, 255424 bytes
MD5: ccbb93e02b37678755f1371cb20aad77
SHA1: e0076b86c78f3b8d4925560c98b89874d5e3bccb
SHA256: F5BD120A72E0B9D24426B053E7244254C87BB7F98A1467B72AC7988E28CA553A
File Size: 255.42 KB, 255416 bytes
MD5: 9246b4431897f8cac167f2df8da82e57
SHA1: 34c51cc36caab2930bc37ed070683fe26ffdde18
SHA256: 740CAE3A06CB37393359872A4E83D4486BD008794AAA68E71CC68EE671CF2337
File Size: 255.41 KB, 255408 bytes
MD5: 0fbee042c1fb9dab86abeb8e847cc292
SHA1: ac7c0cdf743586d4f4fe6458049fd2b45ba69f9e
SHA256: 339CFF5819CC7D2D0889C402D0255118BF45A66707D1CD879A4258C01FB36BC2
File Size: 358.87 KB, 358872 bytes
MD5: 61856a1376866dcc7340a808b2f1c6eb
SHA1: 1fb2c3e7c3ebe37bbe6350cb486bcb909409d468
SHA256: 58E19F3B2989C13294E2F15E6B482E4CEC35FA8B50A0AA1F5768DCCDB8F9EB56
File Size: 356.82 KB, 356824 bytes
MD5: 5197426948a17d4d986e2b22860aec0c
SHA1: 083fe8d4c52bbfe7e2366d433ccc127e67f9deda
SHA256: F2260F6855F6B345FAD8403F7FAB5466E615CFE61ED741E3EACB14A4DDF89C31
File Size: 403.93 KB, 403928 bytes
MD5: 1a01e145cd8124a2dda1f32481a01189
SHA1: b649665bb6b921d6a2c9a3e9d040e433d8552f36
SHA256: 1BE3B710823DC337A3A1F6823020CC40776BD70BDC199CB86630E5D5663702EB
File Size: 402.39 KB, 402392 bytes
MD5: ff6bfbe3b0c23a6ac6f0dd15e0a3b56c
SHA1: 150c386fcc72073eb7eaaac7313d0a7967ecf83a
SHA256: 43DECB63CC49C7F4B6B378FD6BC17DD4777A00F5487AD040875B2F49A0863E97
File Size: 330.51 KB, 330512 bytes
MD5: fd73af9f8c9da85ec1e981c72e2d87ee
SHA1: 339da0d11c296f63ec3b0c0b92e0d162c2700a7a
SHA256: FAB162F13EF2E7DB22D6E8B691D090CA7B8C770BBA11EA59D72D54B65E2DA096
File Size: 379.05 KB, 379048 bytes
MD5: dbb98a19248efc113a3bf167dec9d45d
SHA1: a97b5ce62b2f65aaff1cc99047174456267166b8
SHA256: E4FA2CB7A07C077A4A5A87148E2C5AFF01C1CDEB9BB8DA1ABBD3C3D7E7D35918
File Size: 384.36 KB, 384360 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Comments Captures or records startup environment editor and saves output to a folder
Company Name
  • Fairmont Software, LLC
  • HP Inc.
  • NordVPN S.A.
  • Overwolf Ltd.
  • PineBridge Creek Software Ltd.
  • Piriform Software Ltd
  • Vertex Works Co.
File Description
  • Backs up and restores service state preview panel with local storage
  • Captures or records startup environment editor and saves output to a folder
  • CCleaner
  • CurseForge
  • HP Command Center
  • NordVPN
  • Premium Host - Desktop utility for everyday productivity tasks
File Version
  • 23.3.487.39
  • 23.0.799.15
  • 20.3.28496.603
  • 19.0.15609.737
  • 10.5.1289.920
  • 4.13.1142.103
  • 3.1.2158.385
Internal Name
  • CCleaner64.exe
  • CurseForge.exe
  • HPCommandCenter.exe
  • NordVPN.exe
  • PremiumHost.exe
  • ServiceStatePreviewPanel.exe
Legal Copyright
  • (c) 2023 Fairmont Software, LLC. All rights reserved.
  • Copyright (c) 2015-2026 PineBridge Creek Software Ltd.
  • Copyright © 2021 Overwolf Ltd.. All rights reserved.
  • © 2012-2021 NordVPN S.A.. All rights reserved.
  • © 2020-2023 HP Inc.. All rights reserved.
  • © Piriform Software Ltd. All rights reserved.
Original Filename
  • CCleaner64.exe
  • CurseForge.exe
  • HPCommandCenter.exe
  • NordVPN.exe
  • PremiumHost.exe
  • ServiceStatePreviewPanel.exe
  • StartupEnvironmentEditor.exe
Product Name
  • CCleaner
  • CurseForge
  • HP Command Center
  • NordVPN
  • Premium Host
  • Startup Environment Editor
Product Version
  • Version 23.0.799
  • NordVPN 23.3
  • HP Command Center 19.0
  • CurseForge 20.3
  • 10.5.1289.920
  • 4.13.1142.103
  • 3.1.2158.385
Special Build Release

Digital Signatures

Signer Root Status
ASUSTeK Computer Inc. ASUSTeK Computer Inc. Self Signed
CPUID CPUID Self Signed
Google LLC Google LLC Self Signed
HandBrake Team HandBrake Team Self Signed
Logitech Logitech Self Signed
Show More
Microsoft Corporation Microsoft Corporation Self Signed
NVIDIA Corporation NVIDIA Corporation Self Signed
Premium Host Premium Host Self Signed
Razer Inc. Razer Inc. Self Signed
Service State Preview Panel Service State Preview Panel Self Signed
Startup Environment Editor, O=Fairmont Software, LLC, OU=Application Services, L=Vancouver, S=BC, C=CA Startup Environment Editor, O=Fairmont Software, LLC, OU=Application Services, L=Vancouver, S=BC, C=CA Self Signed
paint.net paint.net Self Signed

File Traits

  • dll
  • HighEntropy
  • ntdll
  • x64

Block Information

Total Blocks: 951
Potentially Malicious Blocks: 49
Whitelisted Blocks: 902
Unknown Blocks: 0

Visual Map

0 0 0 0 x x 0 x 0 0 x x x 0 0 x 0 0 0 0 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x 0 x 0 0 x 0 0 0 x 0 x x x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 x x x x x x x x 0 x 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 EktX �v����(�1�1HO@V�A��H[u_�zk�qw�n�P��jI����������*�m���$�8���&M/�.SLB1_`�V����Q]��@K� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 \k �vT�����(�(X�1�1HO@V�A��_�zk�q{b��P�����������.�m�����$�8წ���&M�=�SB1_T�Vw���%�������AE��D��&��$���L RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Related Posts

Trending

Most Viewed

Loading...