Threat Database Trojans Trojan.Agent.TJW

Trojan.Agent.TJW

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 10,114
Threat Level: 80 % (High)
Infected Computers: 44
First Seen: May 20, 2024
Last Seen: July 29, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.TJW on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to understand its nature and take steps to remove it.

What Is Trojan.Agent.TJW?

Trojan.Agent.TJW is a type of Trojan horse malware, which is a broad category of threats that disguise themselves as legitimate software. The name "Trojan.Agent.TJW" suggests that it is a malicious agent that can perform various actions on an infected system, but the specifics of its behavior and capabilities are not immediately clear. Trojan horses are often used to gain unauthorized access to a system, steal sensitive information, or disrupt normal operations.

How Trojan.Agent.TJW Operates

Malware like Trojan.Agent.TJW typically operates by exploiting vulnerabilities in software or tricking users into installing it. Once installed, it can communicate with its creators or other malicious entities to receive instructions or transmit stolen data. The exact mechanisms used by Trojan.Agent.TJW are not specified, but it's likely that it uses common tactics such as social engineering, drive-by downloads, or exploiting software vulnerabilities to infect systems.

Symptoms of Infection

Systems infected with Trojan.Agent.TJW may exhibit a range of symptoms, including but not limited to, slow performance, frequent crashes, or unusual network activity. You might also notice unfamiliar programs or toolbars installed on your system, or find that your web browser is being redirected to suspicious websites. However, some malware is designed to operate stealthily, so the absence of obvious symptoms does not necessarily mean your system is clean.

  • Unexplained changes to system settings or files
  • Appearance of unwanted pop-ups or advertisements
  • Detection of unfamiliar programs or processes running in the background
  • Increased network activity without apparent cause

How to Remove Trojan.Agent.TJW

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove the malware and any related components.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time the malware was detected.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings changes made by the malware.
  5. After completing the above steps, reboot your computer and perform another scan with your anti-malware tool to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.Agent.TJW requires a combination of technical knowledge and the right tools. By following the steps outlined above and maintaining good security practices, such as keeping your software up to date and being cautious when clicking on links or installing new programs, you can significantly reduce the risk of infection and protect your system from similar threats in the future. Remember, vigilance and proactive security measures are key to safeguarding your digital assets.

Analysis Report

General information

Family Name: Trojan.Agent.TJW
Signature status: No Signature

Known Samples

MD5: 7f08fc4c7b321ad0484301da31dd439c
SHA1: d6de7469e7553e38143beecafe38068c17546af6
SHA256: E2F2705847381440417AE99B97A8B97CDDBC7EC63896B9AF65E090B55D0D9673
File Size: 1.95 MB, 1947136 bytes
MD5: 1f7455ea3e1bbc7a516f6b08e8e0609a
SHA1: 59ca562a9fcf05b81663e14449a09ab32cb6845c
SHA256: 757F5AAD8809C9396795AD30AEAD17BA1A80EDFDD7D7B37A93E2407826CE52B5
File Size: 1.77 MB, 1771008 bytes
MD5: 70522e52c60e3706dc12df5a787ee445
SHA1: 2fe198bdf31ca0b6ccf37868a5f3680192a6c376
SHA256: ABF8F49D92689A7A4C5CB064902892445FB4FA7389B9A08058F7A216F8AA4B41
File Size: 1.77 MB, 1767936 bytes
MD5: ca986a4c01b3346513b31763348845ce
SHA1: 3a97b1701e57db5d7e93b3f8d68f1ee5e0296cec
SHA256: B9487B1E5353BD0063BA1647A9AC84125C57717F8B9390AF323EF1C7D0E5842D
File Size: 1.63 MB, 1634816 bytes
MD5: 54b114af8750d67db8587f160f76e765
SHA1: 1453df25901bd3584f0f35802d3e2c4cdd9b8e16
SHA256: 21F5F495F4306DF2F457B592A4BB3F63211403636F5A5F094981978092390F23
File Size: 1.63 MB, 1634816 bytes
Show More
MD5: 491ad0d2f02bcddafe3b9e736d2aeed0
SHA1: 4b69945e76eba69a9c0eb8307b170d8f5c342282
SHA256: 43DAD112BE3ADC8158C64DC8AEC90FA094916343D8D8831FE22201C4C7ED4CB7
File Size: 2.72 MB, 2718208 bytes
MD5: c9e241f521c93cb0929a5e2995f5033f
SHA1: eaf903abf14505fa88bb7c788df6b5469ceba23f
SHA256: 7B3136E4C02F4F6371E7E4F914EBF7D4C707F8FACAC1D7A28F4D993FD8AF4BB8
File Size: 3.60 MB, 3599360 bytes
MD5: 3206012036e34de7c48b1ecc2389af35
SHA1: 85ede41efcea75b0ae9ed06478c9a5656506ce00
SHA256: 541D93902BDD5A63D13176FDE263A45E7FCDC6C8B4E2250A9A0BB578C1B453E8
File Size: 2.73 MB, 2725376 bytes
MD5: 4c5b7a0493aa74fcf73ad91b8b4d0032
SHA1: 4b5954dadf158dc3a1d9adb8ceecbc7f084bda2b
SHA256: EA0ED69C5F2557015E626DA6DFBE66174900654CD53C167D69853C516A5EC9AC
File Size: 1.77 MB, 1771008 bytes
MD5: d6b4b4f4dd4938f75b9459ed52486331
SHA1: b3420fc4dad318a4d60ce7cf214476abec0b296d
SHA256: F39A710D4915F5A9BCCC44C75FCAD9D8A43CA435311E572A9B87842C67BC07BC
File Size: 1.79 MB, 1785856 bytes
MD5: ff5e960655665e3064239dc535a7796f
SHA1: 3675b0b2253dea89631c0393a89614af35181fe9
SHA256: BECADE38A0780F269E64775DA99F7FFB3C26A46722A6C1B3D20A80C5326D0266
File Size: 1.64 MB, 1635328 bytes
MD5: 956af069d89c8eb1b1753086c749a608
SHA1: b975b34f6e1fa5a7b16c09dee511eb88291a25d4
SHA256: 5B525FE731C516632BF5DAB84E94E43B6248A71C4A72CC32DF8359306E067CC1
File Size: 1.76 MB, 1760256 bytes
MD5: 0076fd1144c4113c3ffd56763fa87dfc
SHA1: 32bd406a35b8161b8a6f5d8809c2ed724aba9391
SHA256: 241A3174774C9E64C934703C5D79EA5F451803C366A31B08BAAD758AE327C19E
File Size: 2.72 MB, 2722816 bytes
MD5: 5d8b098e71102effdc473c46bfd3dd84
SHA1: 041570dfbc0b97639e268eacc6146aec3100b290
SHA256: B7201D7EC692316C1A654C3687E1F81B9CC335122EB014789D4F3F55768F1675
File Size: 1.64 MB, 1642496 bytes
MD5: 2680213d61b740b08b55050ff5e652bb
SHA1: 3a06da95986495727879c64a78524cb1956f778e
SHA256: FA87E7A90E50E03F289C1A5327B45F2BA94E6E9FE046910149A79585C4F0DECD
File Size: 2.30 MB, 2296832 bytes
MD5: 237b85b8820b33787c4d75d1b510b60a
SHA1: 4c5cd35310682eabb879244469454b4631e69866
SHA256: F0B38CDCB52CD5169E90F8992BC8F02AC804252C0227DB773D98005F4E1FDE19
File Size: 2.73 MB, 2734080 bytes
MD5: 85748638c2401458becfb8831311fc08
SHA1: b152a5b3ae6927d6e27c2be3bce463bbdf2131a7
SHA256: F5BF7389F88F6BE9C20D63C00395EC5102FA4C8CDCCF38BB4EC48BA1B30091BE
File Size: 3.59 MB, 3591168 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name
  • Creador De MU
  • DeepShield
  • LTPTeam
  • UGK-SYSTEM
  • WzTeam
  • X-Team
  • ZeroDevs
File Description
  • Antihack
  • DeepShield Anti-Cheat System
  • MHPClient
  • Plugin
  • UGK-SYSTEM
  • ZeroGuard
File Version
  • 1.7.0.0
  • 1.0.0.0
Internal Name
  • Antihack
  • DeepShield
  • MHPClient
  • Plugin
  • UGK-SYSTEM
  • ZeroGuard
Legal Copyright
  • Copyright © 2024
  • Copyright © DeepShield 2021. All Rights Reserved
  • Copyright © LTP-Team.ru 2015
  • Copyright © WzTeam 2024
  • Copyright © ZeroDevs 2024
  • UGK-SYSTEM © 2024
  • UGK-SYSTEM © 2025
  • www.creadordemu.com
Original Filename
  • Antihack.dll
  • DeepSheild.dll
  • MHPClient.dll
  • Plugin.dll
Product Name
  • Creador de MU Antihack
  • DeepShield Anti-Cheat System
  • LTPTeam Antihack
  • MHPClient
  • Plugin
  • UGK-SYSTEM Antihack
  • ZeroGuard
Product Version
  • 1.7.0.0
  • 1.0.0.0

File Traits

  • dll
  • HighEntropy
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 1,627
Potentially Malicious Blocks: 236
Whitelisted Blocks: 583
Unknown Blocks: 808

Visual Map

? ? ? ? x x x ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? x ? ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? x ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 x x x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? x ? ? x x 0 x x x x x x 0 x 0 0 x x x x ? ? ? 0 x ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? x x x 0 ? x ? 0 ? 0 ? ? ? ? x ? 0 ? 0 ? ? ? ? ? 0 x ? ? 0 ? ? ? 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? ? 0 ? 0 ? ? ? ? ? x 0 ? ? 0 x x x ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 ? 0 ? x 0 ? ? ? ? ? ? 0 ? x 0 0 x ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 ? 0 ? 0 0 x 0 0 0 0 ? ? 0 ? ? ? ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? ? ? ? ? 0 ? ? ? ? 0 x x x ? ? ? 0 ? ? ? ? ? 0 ? 0 0 x x x x 0 x 0 x x 0 ? ? ? 0 ? ? ? ? x x x x x x ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? x 0 x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? x x ? ? ? ? ? ? 0 ? 0 x ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? x x ? 0 ? x x 0 0 x ? x 0 ? x ? 0 ? x ? 0 0 ? ? x x ? x x 0 x 0 ? 0 ? x 0 0 x x 0 x x x 0 x x x x x x x ? ? 0 ? ? ? ? ? ? ? x 0 ? 0 0 x 0 0 ? ? ? 0 ? x x x ? x x x x x ? ? x x ? ? ? x x x x x x x 0 0 0 0 0 x x x x x x x x 0 x 0 0 x x 0 x 0 0 0 0 x 0 x x 0 ? ? ? ? ? x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x ? ? 0 ? ? ? 0 x ? ? x x x x ? ? ? ? 0 x 0 x x 0 x 0 0 x x x 0 x x x x 0 0 x ? ? ? ? ? ? 0 ? ? ? ? ? x 0 0 ? ? x ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 x ? x x x ? ? ? 0 ? 0 ? 0 ? 0 ? ? ? 0 ? 0 ? ? 0 ? x 0 ? ? ? ? ? 0 0 ? 0 ? ? x ? ? ? 0 x x x 0 x x 0 0 ? ? ? ? ? ? 0 ? 0 ? x ? ? x ? x ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? 0 ? ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x 0 x 0 x x ? ? ? ? ? ? x ? 0 ? ? ? ? 0 x x 0 x x x x 0 ? ? ? ? x x 0 ? x x ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x ? x x x x x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x ? ? 0 ? ? x x x ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? x ? x ? ? x x ? ? ? ? ? ? ? 0 0 0 0 ? ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? x ? 0 ? ? x ? ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 x x x 0 ? 0 0 0 0 0 0 0 ? ? ? 0 ? ? x x 0 ? ? ? 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x x 0 ? x ? x 0 ? 0 ? ? ? ? ? x ? ? ? ? 0 0 x ? ? x x x ? x x x x x x x x x 0 x x x ? ? x x ? x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? 0 0 0 ? ? ? 0 ? ? ? 0 ? 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 2 0 1 1 0 0 0 0 0 1 1 2 3 1 0 1 0 0 2 2 0 0 1 2 1 1 0 x 0 x x x 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.TJW
  • GameHack.FD

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\d6de7469e7553e38143beecafe38068c17546af6_0001947136.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\59ca562a9fcf05b81663e14449a09ab32cb6845c_0001771008.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\2fe198bdf31ca0b6ccf37868a5f3680192a6c376_0001767936.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\3a97b1701e57db5d7e93b3f8d68f1ee5e0296cec_0001634816.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\1453df25901bd3584f0f35802d3e2c4cdd9b8e16_0001634816.,LiQMAxHB
Show More
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\4b69945e76eba69a9c0eb8307b170d8f5c342282_0002718208.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\eaf903abf14505fa88bb7c788df6b5469ceba23f_0003599360.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\85ede41efcea75b0ae9ed06478c9a5656506ce00_0002725376.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\4b5954dadf158dc3a1d9adb8ceecbc7f084bda2b_0001771008.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\b3420fc4dad318a4d60ce7cf214476abec0b296d_0001785856.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\3675b0b2253dea89631c0393a89614af35181fe9_0001635328.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\b975b34f6e1fa5a7b16c09dee511eb88291a25d4_0001760256.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\32bd406a35b8161b8a6f5d8809c2ed724aba9391_0002722816.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\041570dfbc0b97639e268eacc6146aec3100b290_0001642496.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\3a06da95986495727879c64a78524cb1956f778e_0002296832.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\4c5cd35310682eabb879244469454b4631e69866_0002734080.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\b152a5b3ae6927d6e27c2be3bce463bbdf2131a7_0003591168.,LiQMAxHB