Threat Database Trojans Trojan.Agent.LKGG

Trojan.Agent.LKGG

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 20,596
Threat Level: 80 % (High)
Infected Computers: 2
First Seen: June 13, 2026
Last Seen: August 22, 2026
OS(es) Affected: Windows

Security researchers have issued advisories regarding a stealthy threat detected as Trojan.Agent.LKGG. Classified as a generic Trojan detection, this threat represents a significant risk to system integrity and user privacy. Like many threats in this category, it is designed to infiltrate Windows systems silently, establish a persistent foothold, and facilitate unauthorized activities. Because it often masks its presence behind seemingly legitimate processes, users may remain unaware of the infection for extended periods. This removal report outlines the fundamental characteristics of Trojan.Agent.LKGG, its general behavior, and the recommended steps for complete eradication.

What Is Trojan.Agent.LKGG?

Trojan.Agent.LKGG is a detection name used to identify a malicious Windows PE executable. Threats of this nature are typically designed to act as a backdoor or a delivery mechanism for additional malicious payloads. Analysis of the file structure reveals that the executable carries a self-signed signature. While a legitimate digital signature is generally used to verify the publisher and ensure the file has not been tampered with, a self-signed status indicates that the certificate was generated by the developer rather than a trusted certificate authority. This is a common evasion tactic used to make the file appear more legitimate to the operating system and bypass basic security warnings, while still avoiding standard identity verification protocols.

How Trojan.Agent.LKGG Operates

Once executed on a target system, Trojan.Agent.LKGG generally follows the behavioral patterns of a standard Windows Trojan. Upon execution, the PE file may attempt to write its components to hidden or system directories to avoid detection by the casual user. It often modifies system configurations to establish persistence, ensuring that it is launched automatically every time the operating system starts. By utilizing its self-signed status, the threat attempts to blend into normal system operations. Once established, it may attempt to communicate with remote servers to receive commands, download additional malicious modules, or transmit sensitive information gathered from the compromised host.

Symptoms of Infection

Because Trojan.Agent.LKGG is designed to operate quietly, there are rarely obvious visual symptoms. However, users may observe several indirect signs of compromise:

  • Unexpected degradation in system performance or frequent system freezes.
  • Unexplained network activity, particularly when the computer is idle.
  • Disabled or modified security software, including firewalls and antivirus programs.
  • The sudden appearance of unfamiliar processes running in the Windows Task Manager.
  • System crashes or instability caused by the Trojan interfering with critical system processes.

How to Remove Trojan.Agent.LKGG

Removing Trojan.Agent.LKGG requires a systematic approach to ensure that all malicious components and registry modifications are completely eliminated. Follow these steps to restore your system:

  1. Boot your computer into Safe Mode with Networking to prevent the Trojan from loading automatically and to limit its ability to interfere with the removal process.
  2. Run a full system scan with a reputable anti-malware tool such as SpyHunter to detect and quarantine the malicious PE executable and any associated files.
  3. Uninstall suspicious or unrecognized programs from the Windows Control Panel that may have been installed alongside the threat.
  4. Reset your web browsers (Chrome, Firefox, and Edge) to default settings to remove any malicious extensions, altered proxy settings, or unauthorized homepage modifications.
  5. Reboot your computer normally and perform a final re-scan with your anti-malware software to confirm that Trojan.Agent.LKGG has been completely removed.

Conclusion

Trojan.Agent.LKGG is a serious threat that leverages a self-signed Windows PE executable to infiltrate systems and maintain persistence. Its ability to operate silently makes it a danger to both personal and professional computing environments. Prompt detection and thorough removal are essential to prevent data loss and further system compromise. By utilizing a robust anti-malware solution and following the recommended removal protocol, users can effectively neutralize the threat and restore their system to a secure state.

Analysis Report

General information

Family Name: Trojan.Agent.LKGG
Signature status: Self Signed

Known Samples

MD5: cfb338926bea158ee4fcec4ee691d001
SHA1: 1714e61eb03ebe5299f08dcdeeb6317238dd2a9e
SHA256: B3780535DBE32D92A86EA5E4B572C75E4CFA4EA898A347F8888B00255C5DF1D9
File Size: 131.07 KB, 131072 bytes
MD5: b732d61d3e2e9fde5c8b971ab0e33727
SHA1: ff0a6d72c1d72afd3fd6c6cc4dc5b2c5454da02a
SHA256: 5139C6C7A6DBBCA9E0DC82FA8ADBE048CDFC48DB599F21BC8DC136576A0B08F5
File Size: 7.77 MB, 7769264 bytes
MD5: 83b3661878d72710f075ed5bd59568cf
SHA1: 226f7192d63242b67da628b66a2b18a5908739c9
SHA256: 81D495EC8C341797A27FDFE12739DAE71304F2657E8C09F7F627B2C5DD56BBF3
File Size: 149.86 KB, 149856 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name
  • RedGate Park Utilities, LLC
  • Riverstone Gate Digital GmbH
  • SpringView Gate Digital, GmbH
File Description
  • Clears or reorganizes color wake-on-lan sender safely without touching system files
  • Shows and manages color thumbnail maker on the desktop
  • Shows and manages crash dump service watch on the desktop
File Version
  • 12.13.932.171
  • 7.4.2768.212
  • 5.0.3652.980
Internal Name
  • ColorWakeonLANSender.exe
  • CrashDumpServiceWatch.exe
Legal Copyright
  • (c) 2026 Riverstone Gate Digital GmbH. All rights reserved.
  • Copyright (c) 2016-2022 SpringView Gate Digital, GmbH
  • Copyright (c) 2018-2024 RedGate Park Utilities, LLC
Original Filename
  • ColorThumbnailMaker.exe
  • ColorWakeonLANSender.exe
  • CrashDumpServiceWatch.exe
Product Name
  • Color Thumbnail Maker
  • Color Wake-on-LAN Sender
  • Crash Dump Service Watch
Product Version
  • 7.4.2768.212
  • 5.0.3652.980
Special Build Stable

Digital Signatures

Signer Root Status
Color Thumbnail Maker Color Thumbnail Maker Self Signed
Color Thumbnail Maker Color Thumbnail Maker Self Signed
Color Wake-on-LAN Sender, O=RedGate Park Utilities, LLC, OU=Application Services, L=Dublin, C=IE Color Wake-on-LAN Sender, O=RedGate Park Utilities, LLC, OU=Application Services, L=Dublin, C=IE Self Signed
Crash Dump Service Watch, O=SpringView Gate Digital, GmbH, OU=Platform Operations, L=Seattle, S=WA, C=US Crash Dump Service Watch, O=SpringView Gate Digital, GmbH, OU=Platform Operations, L=Seattle, S=WA, C=US Self Signed

File Traits

  • dll
  • HighEntropy
  • x64

Block Information

Total Blocks: 60
Potentially Malicious Blocks: 13
Whitelisted Blocks: 47
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 x x 0 0 x x x x 0 0 0 x x 0 0 0 0 x x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.LKGG
  • Agent.LKGH
  • Coinminer.CXA
  • Dropper.NFA
  • Kryptik.GDSY
Show More
  • Kryptik.MFRA
  • Trojan.Metasploit.Gen.AF

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n! �v����Bx#��(�1`1�1HO@V�A��H[uN$b"hk`k�ql(��P���!���� ���3������m���gi�V�$�8���l��&MA�~B1_B�������A*�"C��| RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN