Threat Database Trojans Trojan.Agent.UDE

Trojan.Agent.UDE

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 20,610
Threat Level: 80 % (High)
Infected Computers: 2
First Seen: March 12, 2026
Last Seen: June 30, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.UDE on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to understand its nature and how to remove it effectively.

What Is Trojan.Agent.UDE?

Trojan.Agent.UDE is a type of Trojan horse malware, which is a broad category of threats that disguise themselves as legitimate software to gain unauthorized access to a computer system. The name "Trojan.Agent.UDE" suggests that it is a detection name given by security software, indicating that it has been identified as a malicious agent. Trojan horses are known for their ability to evade detection by traditional antivirus programs, making them particularly dangerous.

How Trojan.Agent.UDE Operates

Once installed on a system, Trojan.Agent.UDE can operate in various ways, depending on its intended purpose. It may be designed to steal sensitive information, such as login credentials, credit card numbers, or personal data. It could also be used to download and install additional malware, create backdoors for remote access, or disrupt system operation. The specific actions of Trojan.Agent.UDE can vary, but its primary goal is to compromise the security and integrity of the infected computer.

Symptoms of Infection

Identifying a Trojan infection can be challenging, as these threats often operate silently in the background. However, some common symptoms may indicate the presence of malware like Trojan.Agent.UDE. These include unexpected system crashes, slow performance, unusual network activity, or the appearance of unwanted programs or toolbars. If you suspect that your system is infected, it's crucial to take immediate action to minimize potential damage.

How to Remove Trojan.Agent.UDE

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This will help identify and remove all components of the Trojan.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed around the time the malware was detected.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.Agent.UDE requires careful and thorough action to ensure that all components of the malware are eliminated from your system. By following the steps outlined above and maintaining good security practices, such as keeping your operating system and software up to date, using strong antivirus protection, and being cautious when downloading and installing software, you can help protect your computer from future threats. Remember, the key to dealing with malware is prompt action and a comprehensive removal approach to safeguard your digital security and privacy.

Analysis Report

General information

Family Name: Trojan.Agent.UDE
Signature status: No Signature

Known Samples

MD5: 142da947609a52c962be87aa4abab8a8
SHA1: c8ffbb4807ac7168df2c12b462e182404c0cc447
SHA256: C5C89438F9E34FBEC2C6F9C6B7DB5612FAD15C2902F851C92F74808217EFCABA
File Size: 1.06 MB, 1064448 bytes
MD5: 44b55a1c31fe935dc58b217f3dc9e248
SHA1: 6f78a68476834b637344b31d7f677566b33f724f
SHA256: A525F1FD1C657687686A03BB125F7136450B2F06ABAC036F6FD5F5430B660983
File Size: 729.09 KB, 729088 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name RedLotus
File Description Redlotus
File Version
  • 10.0.19208
  • 1.0.0.0
Product Name
  • EldiaCordLauncher
  • RedLotusModAnalyzer
Product Version
  • 10.0.19208
  • 1.0.0.0

File Traits

  • HighEntropy
  • ntdll
  • x64

Block Information

Total Blocks: 53
Potentially Malicious Blocks: 44
Whitelisted Blocks: 8
Unknown Blocks: 1

Visual Map

0 ? x x x x x x x x 0 x x x x x x 0 x x x x x 0 x x x x x x x x x x x x x x x x x 0 0 x x x x x x x 0 x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.UDE
  • Trojan.Agent.Gen.DFH

Files Modified

File Attributes
c:\users\user\appdata\local\temp\47b1c2dd\eldiacordlauncher.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\47b1c2dd\launcher_2.exe Generic Write,Read Attributes
c:\users\user\downloads\crash.log Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 n�8�tX�jg �� �v xy ����T������%����3bBx��#��$kF&� &�-(�(X�(�)E)�`*J*9*�"-!R0P%1�1HO5,]=�@V�A��B��G�IH[uH�pJ��N$N�O�`U_*X�\te_�zb"hc�wc�zh�ri��j�bk`k�ql(� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 隞놬﫥ǜ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
Show More
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryEvent
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletion
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetIoCompletion
  • ntdll.dll!NtSetSecurityObject
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Cert Store Read
  • CertEnumCertificatesInStore
  • CertOpenSystemStore
Network Winsock
  • accept
  • bind
  • closesocket
  • connect
  • freeaddrinfo
  • getaddrinfo
  • getsockname
  • recv
  • send
  • setsockopt
Show More
  • socket
Network Winsock2
  • WSASocket
  • WSAStartup
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Process Terminate
  • TerminateProcess

Shell Command Execution

C:\Users\Kjghvhzk\AppData\Local\Temp\47B1C2DD\EldiaCordLauncher.exe (NULL)
C:\Users\Kjghvhzk\AppData\Local\Temp\47B1C2DD\Launcher_2.exe (NULL)
"curl" "-k" "-L" "-s" "-o" "C:\Users\Kjghvhzk\AppData\Local\Microsoft\Windows\NtProfileIndex\python.zip.downloading" "https://www.python.org/ftp/python/3.12.7/python-3.12.7-embed-amd64.zip"

Trending

Most Viewed

Loading...