Threat Database Trojans Trojan.Agent.MAG

Trojan.Agent.MAG

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 19,112
Threat Level: 80 % (High)
Infected Computers: 142
First Seen: October 31, 2023
Last Seen: June 24, 2026
OS(es) Affected: Windows

Your computer has been diagnosed with a threat identified as Trojan.Agent.MAG, a type of malicious software that can compromise the security and performance of your system. This report aims to provide you with essential information about this threat, its behavior, symptoms, and the steps you can take to remove it.

What Is Trojan.Agent.MAG?

Trojan.Agent.MAG is categorized as a Trojan, a broad category of malware that operates by deceiving users into installing it on their systems. Unlike viruses, Trojans do not replicate themselves but can cause significant harm by stealing personal data, installing additional malware, or providing unauthorized access to the infected computer. The "Agent" part of its name suggests it might be designed to act on behalf of a remote controller, potentially allowing for a wide range of malicious activities.

How Trojan.Agent.MAG Operates

Trojan.Agent.MAG, like other Trojans, is likely to operate stealthily, attempting to avoid detection by security software. It may create hidden entries in the system registry to ensure it runs every time the computer boots, or it might disguise itself as a legitimate program to deceive both users and security tools. Once installed, it can communicate with its command center to receive instructions, which could range from data theft to using the infected computer as part of a network for distributing spam or malware.

Symptoms of Infection

Infections with Trojan.Agent.MAG can manifest in various ways, depending on its intended purpose. Common symptoms include a general slowdown of the computer, increased internet traffic that you haven't initiated, pop-up messages or unwanted software installations, and changes to your web browser's settings or the appearance of unfamiliar programs on your system. In some cases, the infection might not display any noticeable symptoms, making regular security checks crucial for early detection.

How to Remove Trojan.Agent.MAG

  1. To safely remove Trojan.Agent.MAG, start by booting your computer in Safe Mode with Networking. This will restrict the malware's ability to operate and provide you with a more controlled environment for removal.
  2. Next, perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure your security software is updated to the latest version to increase the chances of detecting and removing the threat.
  3. Uninstall suspicious programs that you do not recognize or that were installed around the time the infection was detected. Be cautious and only remove programs you are sure are not necessary for your system's operation.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious changes that might have been made.
  5. After completing the above steps, reboot your computer and then perform another full scan to ensure that the threat has been fully removed.

Conclusion

Removing Trojan.Agent.MAG requires careful steps to ensure your computer is restored to a safe state. By following the guidelines outlined above and maintaining vigilance through regular security checks and updates, you can protect your system from similar threats in the future. Remember, prevention is key, so always be cautious when downloading software, opening email attachments, or following links from unknown sources.

Analysis Report

General information

Family Name: Trojan.Agent.MAG
Signature status: Hash Mismatch

Known Samples

MD5: 393980ead62f79271f0eba3d86de78c0
SHA1: a1cc0ec32dd5468b10c31cb961f7505ba97281ac
SHA256: 113987351417733277BEEF6A0FB2CF11CAA0CED9AA232069F888D987D28682DD
File Size: 7.87 MB, 7867984 bytes
MD5: 2f237c57266897ee8b41c9a005147f82
SHA1: fb147ef989f15ed1b0299195240d4c944506002e
SHA256: 146D021FCF4E645B8286D76D88253A2EAEDE2D6E0B614505B5DDB37E4BD21F19
File Size: 6.00 MB, 6003464 bytes
MD5: c3c512661edb0c05610b607f48fd58da
SHA1: 750c1e7c6e8e77923098e0d1e182298a0d850e1c
SHA256: C0A4E96380C7218F30CEB21305403327E0507412937D85F8C6674ECBE67A4E26
File Size: 5.94 MB, 5940488 bytes
MD5: d22c66cd590e8074fa8e70f407ff3daf
SHA1: 3a6a8e73e260be59e7abbc9af3ee63c29374b1bb
SHA256: A9DCDF5260019C8A97E23F98501E8053C6687B303E75097B4C4A977A789DCA28
File Size: 5.93 MB, 5934856 bytes
MD5: d5a5727d21e6575e0b71e15acb6609e0
SHA1: 7baaf31428eaa092d59de1c662ad4bead048dc95
SHA256: 0773FAF3B07302C82F681B112DF893C75F8EC382A6C7ACE7F64C3A15F02663DF
File Size: 7.81 MB, 7813680 bytes
Show More
MD5: 02b8dae224bfc4eeaaf47e992930d2e5
SHA1: f2f76e8ba02d30ad7b698bc36d70b41e49604b10
SHA256: B435EA91CE25F5F042EB9E3344ABB5E06935D4DFE78FF31966ADA817948094F2
File Size: 5.94 MB, 5935368 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have resources
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description WMI Provider Host
File Version 10.0.26100.3323 (WinBuild.160101.0800)
Internal Name Wmiprvse.exe
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename Wmiprvse.exe
Product Name Microsoft® Windows® Operating System
Product Version 10.0.26100.3323

Digital Signatures

Signer Root Status
FIRMA DE CODIGO JAVA SECRETARIA GENERAL DE ADMINISTRACION DIGITAL AC Componentes Informáticos Hash Mismatch
Surfshark B.V. GlobalSign Code Signing Root R45 Hash Mismatch
Martin Tofall Sectigo Public Code Signing Root R46 Hash Mismatch

File Traits

  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • vmp section variant
  • x64

Block Information

Total Blocks: 1,805
Potentially Malicious Blocks: 182
Whitelisted Blocks: 417
Unknown Blocks: 1,206

Visual Map

0 ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? 0 ? 0 0 ? ? 0 ? ? ? ? ? ? x ? 0 ? ? ? ? 0 ? ? ? x 0 ? 0 ? ? 0 ? 0 ? ? ? x ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? x ? ? 0 ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? 0 ? 0 x x x 0 ? 0 ? ? ? ? ? 0 ? ? 0 x ? ? ? 0 0 ? 0 ? x ? ? ? 0 ? ? 0 x x ? 0 0 ? x x ? ? 0 0 ? ? ? 0 x ? ? ? x 0 ? ? ? ? ? ? ? ? ? ? x ? ? ? x ? 0 x ? x ? ? ? ? ? x x ? ? ? ? ? ? ? ? ? 0 ? ? ? ? x ? ? 0 ? ? ? x 0 ? 0 0 ? ? 0 0 ? ? ? x ? ? ? ? ? x ? ? ? 0 ? 0 ? ? 0 ? ? ? 0 ? x 0 ? 0 0 ? ? ? ? ? 0 ? ? ? ? ? 0 0 ? ? x ? 0 0 ? 0 ? ? ? ? 0 ? ? ? ? ? x ? x ? 0 ? x ? ? ? ? ? ? ? x ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? x 0 ? 0 0 ? ? 0 ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? x ? 0 ? ? ? 0 0 0 ? ? 0 ? ? ? 0 ? 0 x ? ? ? ? ? ? 0 x ? x ? ? 0 0 ? ? ? ? ? ? ? 0 x ? 0 ? ? 0 ? ? 0 0 ? 0 ? ? 0 ? 0 0 ? 0 x 0 ? 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? x ? ? 0 ? ? ? ? x 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? x ? 0 ? ? ? 0 ? ? ? ? 0 ? ? ? x x x ? ? ? ? ? ? 0 ? ? 0 ? ? ? x 0 x x ? ? x ? ? ? ? x ? ? 0 ? ? 0 x ? 0 ? ? ? x ? ? ? 0 ? ? 0 ? 0 ? ? ? ? 0 ? ? 0 0 ? 0 ? x ? 0 0 x x ? ? x ? 0 0 0 x ? ? ? 0 ? ? 0 x 0 ? ? ? ? ? ? ? ? ? ? x ? ? ? ? x x 0 ? ? ? 0 ? ? ? ? ? 0 0 0 ? ? ? 0 0 0 ? ? ? ? ? ? ? ? 0 ? ? ? x 0 ? ? 0 ? 0 x ? ? ? ? 0 0 x ? ? 0 ? ? ? ? ? x ? ? 0 0 ? 0 ? ? ? ? 0 ? 0 0 ? ? 0 0 ? ? 0 ? ? ? ? ? ? ? ? 0 ? x ? 0 x x ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x x 0 ? 0 0 ? ? ? ? ? ? ? 0 x 0 ? ? ? 0 ? 0 ? 0 ? ? 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? x ? x ? ? ? ? 0 ? ? x ? 0 ? 0 ? ? ? ? ? ? ? ? ? x x ? ? ? 0 x ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? 0 ? 0 ? x ? x ? 0 ? 0 ? ? ? ? ? ? ? x ? 0 ? ? ? ? x ? ? 0 ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? x 0 0 ? 0 ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? x ? 0 0 ? ? ? ? 0 ? ? ? 0 0 x ? ? 0 ? ? ? ? ? ? 0 0 ? ? 0 ? ? ? 0 0 x ? ? ? 0 0 ? 0 ? ? ? 0 x ? ? ? ? ? 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 ? x ? 0 ? ? 0 0 ? x x x ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? x 0 ? ? 0 ? ? 0 ? 0 x x x ? x ? ? ? ? ? x 0 ? ? x ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? x ? 0 ? x ? ? 0 ? ? x 0 ? ? ? ? x ? x ? 0 ? 0 ? ? x ? ? ? 0 ? x 0 ? 0 0 ? ? ? x ? ? 0 ? ? x ? ? ? 0 ? 0 ? ? ? ? 0 ? x 0 ? ? x 0 ? ? 0 ? ? 0 x ? ? ? ? ? ? 0 x ? ? ? x ? ? ? ? 0 ? 0 ? ? ? ? 0 0 0 0 ? 0 ? ? ? ? x ? ? ? ? ? x ? ? ? ? ? ? 0 ? ? ? ? ? x ? ? ? 0 ? x ? ? ? ? 0 x ? ? 0 x 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? 0 ? ? ? x ? ? x ? x ? 0 x 0 ? ? ? 0 ? ? ? 0 0 ? ? ? 0 0 ? ? ? 0 ? ? ? ? x 0 0 ? x ? x x ? 0 ? ? ? 0 0 ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? 0 ? ? ? 0 0 0 0 x ? ? ? ? ? 0 ? ? x ? 0 x ? ? x ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 ? ? ? ? ? 0 x ? 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 0 ? 0 0 ? ? x ? x ? ? 0 x ? ? ? ? ? ? ? ? ? ? ? ? ? x x ? ? ? 0 ? ? 0 ? 0 0 ? ? 0 0 ? ? ? ? ? ? 0 ? ? ? ? 0 0 ? ? ? 0 ? 0 ? 0 0 x x ? 0 0 ? ? 0 x ? 0 ? ? x ? ? ? ? ? ? ? x ? ? x ? x ? x ? 0 0 ? ? ? ? x ? x ? 0 x ? ? 0 x ? x ? ? 0 0 ? ? ? ? 0 ? 0 ? ? 0 ? ? ? ? 0 x ? 0 ? x 0 x ? 0 ? ? 0 ? ? ? 0 ? 0 0 0 0 ? ? ? ? ? ? ? ? ? x ? x ? ? ? ? ? 0 ? 0 ? 0 ? ? ? ? 0 x ? 0 ? 0 0 ? 0 ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? 0 ? ? ? ? 0 ? ? ? x ? ? 0 x ? 0 ? 0 ? ? x x ? ? ? ? ? ? 0 0 x ? ? ? ? 0 ? ? ? ? 0 0 ? 0 x ? 0 ? ? ? ? 0 0 ? ? ? x ? x 0 0 ? ? ? 0 x ? ? ? ? x 0 x ? ? 0 0 x x ? ? x 0 ? 0 0 ? ? x 0 ? 0 ? 0 ? ? ? x ? ? x ? 0 ? ? ? ? ? 0 ? 0 ? 0 ? 0 0 0 ? 0 x x 0 ? ? ? 0 x ? ? 0 ? ? ? 0 x 0 ? 0 ? 0 ? 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? x ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? ? ? ? 0 ? ? ? 0 x ? ? ? ? 0 x ? ? ? ? 0 ? 0 0 ? ? ? 0 ? ? x 0 x ? ? ? ? ? ? ? ? ? ? 0 x ? ? 0 ? ? ? x ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? 0 x 0 0 0 0 ? ? ? ? ? ? ? 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
Show More
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...