Threat Database Trojans Trojan.Agent.Gen.BNJ

Trojan.Agent.Gen.BNJ

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 9,819
Threat Level: 80 % (High)
Infected Computers: 15
First Seen: April 2, 2026
Last Seen: May 28, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.Gen.BNJ on your system indicates a potential security threat. This name suggests a generic detection for a Trojan-type threat, which can have various implications for your computer's security and performance. It is essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.

What Is Trojan.Agent.Gen.BNJ?

Trojan.Agent.Gen.BNJ is a detection name that refers to a type of malicious software (malware) known as a Trojan. Trojans are malicious programs that can disguise themselves as legitimate software, allowing them to bypass security measures and gain unauthorized access to a computer system. The ".Gen" part of the name suggests that this is a generic detection, indicating that the malware may not be a specific, known variant but rather a broader category of threats.

How Trojan.Agent.Gen.BNJ Operates

Trojan-type malware, including Trojan.Agent.Gen.BNJ, typically operates by infiltrating a computer system through various means, such as exploiting vulnerabilities, disguising itself as legitimate software, or being downloaded inadvertently by a user. Once inside, it can perform a range of malicious activities, including stealing sensitive information, installing additional malware, or providing unauthorized access to the infected system. The exact behavior can vary widely depending on the specific goals of the malware authors.

Symptoms of Infection

Systems infected with Trojan.Agent.Gen.BNJ or similar malware may exhibit a variety of symptoms, although some infections may not display noticeable signs. Common indicators of a Trojan infection include unexpected changes to system settings, appearance of unknown programs or icons, increased network activity without apparent cause, slow system performance, and frequent crashes or freezes. Additionally, users might notice that their personal data is being stolen or that their system is being used for malicious activities without their knowledge.

  • Unexplained changes to system settings or files
  • Appearance of unfamiliar programs or icons
  • Increased network activity
  • Slow system performance
  • Frequent system crashes or freezes

How to Remove Trojan.Agent.Gen.BNJ

  1. Boot your computer in Safe Mode with Networking to limit the malware's ability to interfere with the removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all traces of the malware.
  3. Uninstall any suspicious programs that were installed around the time of the infection. Be cautious and only remove programs that you are certain are malicious or unnecessary.
  4. Reset your web browsers (e.g., Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the malware.
  5. Reboot your computer and perform another scan with your anti-malware tool to ensure that all malware components have been removed.

Conclusion

Removing Trojan.Agent.Gen.BNJ from your system requires careful and systematic steps to ensure that all components of the malware are eliminated. By following the removal guide and maintaining good security practices, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when downloading and installing programs, you can protect your system from future infections. Remember, prevention and vigilance are key to maintaining computer security in today's digital landscape.

Analysis Report

General information

Family Name: Trojan.Agent.Gen.BNJ
Signature status: Self Signed

Known Samples

MD5: c68683bc7f0e7fc45a707855e1a285e1
SHA1: 66712a93b89d8bb26017b33001775dad8a16b889
SHA256: FBD625897FDF32025A63BAB4BCA684D7E996416C743D03B3BDE2D64B428B7FDC
File Size: 398.47 KB, 398472 bytes
MD5: 0a89e7518d5da2130bb9db222b13bc45
SHA1: 9b4a2dbd13f421755e97336cc5dfda44383821c4
SHA256: 6A9C1FA9530FE4D54F727111300B8FB80F380EA03C363E80AC5A24BDF18DAADE
File Size: 410.43 KB, 410432 bytes
MD5: dac7c3aa83dd6774651945646bb40fbf
SHA1: 360fedb977091336f17cb169202021fd2645824a
SHA256: BEEAECBD9BCBF4B0D8D64259511F5ABECB1DC93599CCD9FF097066963627DCA9
File Size: 401.92 KB, 401920 bytes
MD5: e6550a4d980b46a809fd8b824891761e
SHA1: 40f9c0efa5381d78e09405adca82c5e6d7fe3537
SHA256: F50FCDDD09409B3B4C23684C3120A8320E325D4C9C5FFF5DBC3587B65A7D305D
File Size: 344.58 KB, 344576 bytes
MD5: f70d796e1e7a4ca917b680d723fef9d1
SHA1: e29e02b1ef99350e0f267b4a609ae42ead6e0c81
SHA256: 420470634F5CF449E7835827FFE2D60393A1BDE789275CDE108B70F28AB39FD4
File Size: 381.95 KB, 381952 bytes
Show More
MD5: d5b01e27925dad8c3ac7c273ac807c51
SHA1: 147a15819c13bc4649dbd1753184b6d8e18e1dc8
SHA256: 09B0264DC382266410BB4EE5670389DE7E10838600912E0AE89CB382398AC158
File Size: 369.66 KB, 369664 bytes
MD5: b1cf5545bac4ebd80622ad4a6d75fcda
SHA1: 4812fde9ab529b4dd9a8b878aff5ce96ada5e886
SHA256: D16405DB1F026CA6820BE7E263C2E3A539B33DEA2C81894EB4B01A2E5FF46476
File Size: 414.21 KB, 414208 bytes
MD5: d23b435ca6b5c2339422d9da3071387e
SHA1: 56acdd00f5c7fe01262000a8cf44db9b82602a1c
SHA256: B36C1CCB7DDD9B35BC78982B1BEB0A1084BF3703AA5788E549E0B695ADC059CF
File Size: 368.13 KB, 368128 bytes
MD5: a929fa0790721d98693b4b8f9d260d22
SHA1: 68fd65b44be779ad59778482a7e2e268cd6911f9
SHA256: E7D7B3899A95BD7F6233AF60DE2338E1A8D99B6E10ED9E7C3DBD032877EC1E09
File Size: 370.69 KB, 370688 bytes
MD5: 8366b25c94a18f62bdcbec8a8f82073e
SHA1: 2d910893a0f18c228c546aa17a0012645ac49c97
SHA256: 5B2886D27A1A29779FFE0CE85BF17F00E4F33148B79138AFED7EA8752DED8CB2
File Size: 370.62 KB, 370616 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Comments Google Update Service
Company Name
  • be quiet!
  • Dell Inc.
  • Google LLC
  • JetBrains s.r.o.
  • Microsoft Corporation
  • OBS Project
  • Python Software Foundation
  • Samsung Electronics Co., Ltd.
  • Slack Technologies, LLC
File Description
  • Antimalware Service Executable
  • be quiet! System Power Monitor
  • Dell Display Manager
  • Google Update Service
  • Microsoft Recall
  • OBS Studio
  • Python Interpreter
  • Samsung Magician SSD Tool
  • Slack Desktop
  • WebStorm
File Version
  • 537.57.35.67
  • 132.0.6913.129
  • 22.1.493.51
  • 15.13.26561.739
  • 10.8.691.140
  • 10.5.2496.960
  • 10.1.21677.3005
  • 4.13.2908.177
  • 4.12.3831.322
  • 1.12.1992.123
Internal Name
  • BQSysPwrMon.exe
  • DDM.exe
  • GoogleUpdate.exe
  • Microsoft.Recall.exe
  • MsMpEng.exe
  • obs64.exe
  • python.exe
  • Samsung Magician.exe
  • slack.exe
  • webstorm64.exe
Legal Copyright
  • Copyright 2023 Google LLC. All rights reserved.
  • Copyright © 2023 Microsoft Corporation. All rights reserved.
  • Copyright © 2023 Samsung Electronics Co., Ltd.. All rights reserved.
  • Copyright © 2026 be quiet!. All rights reserved.
  • © 2015-2020 OBS Project. All rights reserved.
  • © 2016-2026 JetBrains s.r.o.. All rights reserved.
  • © Dell Inc. 2020. All rights reserved.
  • © Microsoft Corporation. All rights reserved.
  • © Python Software Foundation 2023. All rights reserved.
  • © Slack Technologies, LLC. All rights reserved.
Legal Trademarks
  • Google and the Google logo are trademarks of Google LLC.
  • Microsoft® is a registered trademark of Microsoft Corporation.
  • Samsung is a registered trademark of Samsung Electronics Co., Ltd.
Original Filename
  • BQSysPwrMon.exe
  • DDM.exe
  • GoogleUpdate.exe
  • Microsoft.Recall.exe
  • MsMpEng.exe
  • obs64.exe
  • python.exe
  • Samsung Magician.exe
  • slack.exe
  • webstorm64.exe
Private Build d3078568e5e4
Product Name
  • be quiet! System Power Monitor
  • Dell Display Manager
  • Google Update
  • Microsoft Recall
  • OBS Studio
  • Python
  • Samsung Magician
  • Slack
  • WebStorm
  • Windows Defender
Product Version
  • Python 22.1
  • OBS Studio 4.13
  • 537.57.35.67
  • 132.0.6913.129
  • 15.13.26561.739
  • 10.8.691.140
  • 10.5.2496
  • 10.1.21677
  • 4.12
  • 1.12.1992
Special Build Release

Digital Signatures

Signer Root Status
Grammarly, Inc. Grammarly, Inc. Self Signed
Jan Jan Self Signed
Notion Labs, Inc. Notion Labs, Inc. Self Signed

File Traits

  • dll
  • HighEntropy
  • ntdll
  • x64

Block Information

Total Blocks: 913
Potentially Malicious Blocks: 50
Whitelisted Blocks: 863
Unknown Blocks: 0

Visual Map

0 0 0 0 x x 0 0 0 0 x x 0 x x x x 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 x x x x x x 0 x x 0 x x x x x x x 0 0 x 0 0 x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x x x x x x 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Show More
  • Trojan.ShellcodeRunner.Gen.KC

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Vl( �v �Z����Bx#��(�1`1�1HO@V�A��H[uH�pN$_�zk`k�ql(�{b��P���!���� ���3�����������m�Ù��gi�V����$�8წ���l��&MA�~�=�SB1_B��T�Vw�`�V��%���������AE�Q]��D��&�� RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Related Posts

Trending

Most Viewed

Loading...