Threat Database Trojans Trojan.Agent.Gen.CLB

Trojan.Agent.Gen.CLB

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 8,883
Threat Level: 80 % (High)
Infected Computers: 12
First Seen: May 4, 2026
Last Seen: July 13, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.Gen.CLB on your system indicates a potential security threat. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to take immediate action to remove it. In this report, we will provide you with general guidance on how to deal with this threat and prevent future infections.

What Is Trojan.Agent.Gen.CLB?

Trojan.Agent.Gen.CLB is a type of Trojan horse malware, which is a broad category of threats that can perform a variety of malicious actions on an infected system. The name "Trojan" refers to the fact that this type of malware often disguises itself as a legitimate program or file, allowing it to evade detection and gain access to the system. The ".Gen" suffix suggests that this is a generic detection, indicating that the malware may not be a specific, known variant, but rather a newly discovered or unidentified threat.

How Trojan.Agent.Gen.CLB Operates

Trojan horse malware like Trojan.Agent.Gen.CLB can operate in a variety of ways, depending on the intentions of the attacker. Some common actions include stealing sensitive information, such as login credentials or financial data, installing additional malware or viruses, and providing unauthorized access to the system. Trojan horses can also be used to disrupt system operation, causing crashes, freezes, or other problems. In some cases, they may also be used to recruit the infected system into a botnet, allowing the attacker to control the system remotely.

Symptoms of Infection

Systems infected with Trojan.Agent.Gen.CLB may exhibit a range of symptoms, including slow system performance, unexpected crashes or freezes, and unusual network activity. You may also notice that your system is behaving erratically, or that certain programs or functions are not working as expected. In some cases, you may receive alerts or warnings from your security software, indicating that a threat has been detected. It's essential to take these symptoms seriously and take immediate action to remove the malware.

  • Unexplained changes to system settings or configuration
  • Appearance of unfamiliar programs or icons
  • Unusual or suspicious network activity
  • System crashes or freezes
  • Slow system performance

How to Remove Trojan.Agent.Gen.CLB

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove the malware.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform a follow-up scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Agent.Gen.CLB from your system requires careful attention to detail and a thorough understanding of the malware removal process. By following the steps outlined in this report, you can help to ensure that your system is clean and secure. It's also essential to take steps to prevent future infections, including keeping your operating system and software up to date, using strong antivirus protection, and being cautious when opening email attachments or downloading files from the internet. Remember, a clean and secure system is the best defense against malware and other online threats.

Analysis Report

General information

Family Name: Trojan.Agent.Gen.CLB
Signature status: No Signature

Known Samples

MD5: 9c04ee265a82db4ce7a4cde4d89d0055
SHA1: 5c8c62e7bf1eee0de6d2d3e9d7caca535896ba92
SHA256: D13D3DE76A86AB875C2ACD0D28C866928C842B206D1F83EB3CC5886811FD24D2
File Size: 40.96 KB, 40960 bytes
MD5: f29432f7ad9571119dca3cd5c9b4bf89
SHA1: c68728ce1137e3dd255adcac69182985d85a1ecf
SHA256: 9EF81E30DE63B209B970C48D63F893CEDB17F958CD9BAFEBF27CCA6AEE4EAA48
File Size: 44.54 KB, 44544 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name
  • MediaTek Inc.
  • Silicon Graphics Inc.
File Description
  • NVIDIA Container Local Service Launcher
  • Perl Script Host
File Version
  • 10.5.8870.59
  • 5.4.1270.12
Internal Name
  • IntelGFXPers
  • LuaVM
Legal Copyright
  • 2018 MediaTek Inc.. All rights reserved.
  • 2024 Silicon Graphics Inc.. All rights reserved.
Original Filename
  • igfxpers.exe
  • node.exe
Product Name
  • NVIDIA Container Local Service Launcher
  • Perl Script Host
Product Version
  • 10.5.8870.59
  • 5.4.1270.12

File Traits

  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 50
Potentially Malicious Blocks: 31
Whitelisted Blocks: 1
Unknown Blocks: 18

Visual Map

x ? x x x ? x x x x x ? ? x x 0 ? x x ? x ? x x x x x x x ? x ? ? x ? x x ? ? ? x ? ? ? ? x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Files Modified

File Attributes
c:\users\user\appdata\roaming\microsoft\windows\services\winhost.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\roaming\microsoft\windows\services\winhost.exe Read Attributes,Synchronize,Write Attributes
c:\users\user\appdata\roaming\microsoft\windows\services\winhost.exe Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\explorer\advanced::ictrlpath c:\users\user\downloads\5c8c62e7bf1eee0de6d2d3e9d7caca535896ba92_0000040960 RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer\advanced::ictrldata ⼸痥當畵畱畵誊畵痍畵畵畵电畵畵畵畵畵畵畵畵畵畵畵畵畵畵畵畵畵疭畵橻篏셵롼쵔㥴咸ᴡ؜Օᨇܒ᠔ᙕᬔᨛ唁ဗݕᬀ᱕唛㨱唦ᨘထ硛罸畑畵畵畵恖钾Ē쟐Ē쟐Ē쟐聫웖ē쟐聫웑ę쟐Ē쟑Ř쟐語웕ē쟐語월Ę쟐語윯ē쟐語웒ē쟐ᰧᴖĒ쟐畵畵畵畵〥畵異䐼Ὑ畵畵畵畵疅畗睾䝻㥵畵❵畵畵畵 RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer\advanced::ictrlpath c:\users\user\downloads\c68728ce1137e3dd255adcac69182985d85a1ecf_0000044544 RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer\advanced::ictrldata ⼸痥當畵畱畵誊畵痍畵畵畵电畵畵畵畵畵畵畵畵畵畵畵畵畵畵畵畵畵疭畵橻篏셵롼쵔㥴咸ᴡ؜Օᨇܒ᠔ᙕᬔᨛ唁ဗݕᬀ᱕唛㨱唦ᨘထ硛罸畑畵畵畵恖颾Ē쯐Ē쯐Ē쯐聫쫖ē쯐聫쫑ę쯐Ē쯑Ş쯐語쫕ē쯐語쫔Ę쯐語쬯ē쯐語쫒ē쯐ᰧᴖĒ쯐畵畵畵畵〥畵異ሤὋ畵畵畵畵疅畗睾䝻⵵畵ⅵ畵畵畵 RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtCopyFileChunk
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDeviceIoControlFile
Show More
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetSecurityObject
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Related Posts

Trending

Most Viewed

Loading...