Threat Database Trojans Trojan.Agent.TJ

Trojan.Agent.TJ

By CagedTech in Trojans

The detection of Trojan.Agent.TJ on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise your computer's security and potentially steal sensitive information or disrupt system operations. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Agent.TJ?

Trojan.Agent.TJ is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate programs or files. The ".TJ" suffix may indicate a specific variant or classification within the Trojan horse category, but without more information, it's challenging to determine its exact characteristics or behaviors. Trojan horses are known for their ability to deceive users into installing them, often by masquerading as useful applications or attaching themselves to legitimate software downloads.

How Trojan.Agent.TJ Operates

Once installed, Trojan.Agent.TJ can operate in various ways, depending on its intended purpose. It may create backdoors for remote access, allowing attackers to control your computer, steal data, or use your system for malicious activities like spreading spam or participating in botnet attacks. Some Trojans are designed to capture keystrokes, potentially leading to the theft of login credentials, credit card numbers, or other sensitive information. They might also modify system settings, disable security software, or install additional malware to further compromise your computer's security.

Symptoms of Infection

Identifying a Trojan infection can be challenging because these malware types often do not exhibit obvious symptoms. However, you might notice your computer behaving strangely, such as running more slowly than usual, experiencing frequent crashes, or displaying unfamiliar programs or toolbars in your web browser. Sometimes, Trojans can lead to unexpected changes in system settings or the appearance of suspicious files and folders. If you suspect your computer is infected, it's crucial to act quickly to minimize potential damage.

How to Remove Trojan.Agent.TJ

  1. Enter Safe Mode with Networking: This will help prevent the malware from spreading or interfering with the removal process. Restart your computer and press the key to enter safe mode (this varies by operating system but is often F8 for Windows).
  2. Perform a Full Scan with a Reputable Tool: Utilize a trusted anti-malware program, such as SpyHunter, to scan your computer thoroughly. Ensure your antivirus and anti-malware software are updated to the latest versions to increase the chances of detecting and removing the threat.
  3. Uninstall Suspicious Programs: Go through your installed programs and remove any that you don't recognize or that were installed around the time you suspect the infection occurred.
  4. Reset Your Web Browsers: Resetting browsers like Chrome, Firefox, and Edge can help remove any malicious extensions or settings changes made by the Trojan. Each browser has a reset option in its settings or preferences menu.
  5. Reboot and Re-scan: After completing the above steps, restart your computer and perform another full scan with your anti-malware tool to ensure that the threat has been completely removed.

Conclusion

Removing Trojan.Agent.TJ from your computer requires careful and immediate action to prevent further damage. By understanding the nature of this threat and following the steps outlined above, you can effectively eliminate the malware and protect your system from future infections. Remember, prevention is key; always be cautious when downloading software, avoid suspicious links, and keep your security software up to date to safeguard your computer against evolving threats.

Analysis Report

General information

Family Name: Trojan.Agent.TJ
Signature status: No Signature

Known Samples

MD5: 3ef3e8c231c44ff3c4d1f24a008c9276
SHA1: a386faf6294acaf60de28e54600ef2f5cc7d926f
SHA256: 53AF588AFFA042E3E28E7963F0E061B56B80C4A4CB5AEC7B742471D7F1CE14BD
File Size: 2.34 MB, 2336388 bytes
MD5: 29649922a15bf7852f53aa37c91e88d9
SHA1: b3223d27d483af775312de8729dada9e6f91bb41
SHA256: 91ABD1120EBE33833663E97B75D6751E303966089DED90D9A970E7826BD6B1BE
File Size: 436.74 KB, 436736 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup.
Company Name UltraUtils, Inc.
File Description BmpRgbEditor Setup
Product Name BmpRgbEditor
Product Version 1.2.2.3

File Traits

  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 1,659
Potentially Malicious Blocks: 7
Whitelisted Blocks: 1,544
Unknown Blocks: 108

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 ? 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? 0 0 0 ? ? 0 0 ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 ? 0 x ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 ? ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 ? ? ? ? ? 0 ? 0 0 0 ? 0 ? 0 ? 0 0 ? 0 ? 0 ? 0 0 ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 x 0 0 0 0 0 ? ? ? ? ? 0 ? ? ? 0 0 ? ? ? ? 0 ? 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 0 ? ? ? ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 2 3 1 1 1 1 0 1 1 1 0 0 0 0 0 0 2 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 2 2 0 1 0 0 1 0 0 0 0 0 0 0 0 ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\is-avuha.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-dbptb.tmp\a386faf6294acaf60de28e54600ef2f5cc7d926f_0002336388.tmp Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 0k 8��8tXz��B�8 �� �6 �v z 5� �Z xy ��T�B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1` RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �� 6 xy* �/��Y�d�kP~� ��ރ�p��^�o���zee)Vs} kP~ ��1���7 ���ﺃee�� ��1��fe��h�n RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 1k8��8tXz��B�8 �� �6 �v z 5� �Z xy ��T�B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1` RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
  • ShellExecute
User Data Access
  • GetUserObjectInformation

Shell Command Execution

"C:\Users\Xrbbvfva\AppData\Local\Temp\is-DBPTB.tmp\a386faf6294acaf60de28e54600ef2f5cc7d926f_0002336388.tmp" /SL5="$E031E,1447850,971264,c:\users\user\downloads\a386faf6294acaf60de28e54600ef2f5cc7d926f_0002336388"
(NULL) c:\users\user\downloads\a386faf6294acaf60de28e54600ef2f5cc7d926f_0002336388 /VERYSILENT

Related Posts

Trending

Most Viewed

Loading...