Threat Database Trojans Trojan.Agent.ZFKD

Trojan.Agent.ZFKD

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 19,630
Threat Level: 80 % (High)
Infected Computers: 40
First Seen: November 8, 2024
Last Seen: July 8, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.ZFKD on your system indicates a potential security threat that requires immediate attention. This Trojan-type threat can compromise your computer's integrity and put your personal data at risk. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Agent.ZFKD?

Trojan.Agent.ZFKD is a type of malware that can infiltrate your system without your knowledge or consent. The term "Trojan" refers to a broad category of malicious software that disguises itself as legitimate or harmless. The ".Agent.ZFKD" suffix suggests a specific variant or identifier assigned by security software. While the exact characteristics of this threat may vary, its primary goal is to gain unauthorized access to your system, steal sensitive information, or disrupt normal computer operations.

How Trojan.Agent.ZFKD Operates

Once inside your system, Trojan.Agent.ZFKD can operate in various ways, depending on its design and purpose. It may attempt to connect to remote servers to receive instructions or transmit stolen data. This malware can also create backdoors, allowing hackers to access your system remotely and execute malicious commands. Additionally, it may install other types of malware, such as spyware, adware, or ransomware, to further compromise your system and data.

Symptoms of Infection

Identifying a Trojan.Agent.ZFKD infection can be challenging, as it often disguises itself as legitimate software or operates in the background. However, some common symptoms may indicate a potential infection, including slower system performance, unexpected pop-ups or ads, unauthorized changes to system settings, or suspicious network activity. If you suspect that your system is infected, it is crucial to take immediate action to prevent further damage.

How to Remove Trojan.Agent.ZFKD

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Run a full scan with a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the Trojan.Agent.ZFKD malware.
  3. Uninstall any suspicious programs or applications that may be related to the infection, as they may be compromised or malicious.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and run another full scan to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.Agent.ZFKD from your system requires a combination of technical expertise and caution. By following the steps outlined above and maintaining good security practices, such as regularly updating your operating system and software, using strong passwords, and avoiding suspicious downloads, you can help prevent future infections and protect your personal data. Remember to stay vigilant and monitor your system for any signs of malicious activity, and consider seeking professional help if you are unsure about any aspect of the removal process.

Analysis Report

General information

Family Name: Trojan.Agent.ZFKD
Signature status: No Signature

Known Samples

MD5: 95af2eb32adb3b9051b9abf5f64db31b
SHA1: bf85766fb55e86843e512580b712d54250cd97fb
File Size: 1.15 MB, 1151488 bytes
MD5: 4425b63d0d2ed4c782904c4167c8f79f
SHA1: b70b91b60f2c8c249503f15a62c7bbcf24e24c6c
SHA256: 67DAB970648CEC8D7069A76F73AF2AC0AB9C2F945FD5D48EA097CBF89C2680D8
File Size: 2.88 MB, 2883072 bytes
MD5: ef78734b1e5dc6886da4391064141e4b
SHA1: b32c1eb85ada108fe8ca88e7b25f6632d0bf9fa6
SHA256: 316C1B7DD64F902BDB1D31AD861C54DD269345791CB2888EC5AC2DE87172B2E4
File Size: 1.02 MB, 1024512 bytes
MD5: 03436615aa4d301e83e33e93b8302de8
SHA1: 905c0d1d2c104360af9865c69ac1fc769e868992
SHA256: 9831F5FA4C7C17F47DE676A83D6D1EF14BC47D12B327089EF14B623642846600
File Size: 1.51 MB, 1507840 bytes
MD5: c924c64d581eec1c632878b22ead52b6
SHA1: 97d6ebe7ec21538db3779bbda648a9cc9aa60e30
SHA256: 6CC01D26523A78A3F8EFE4D8BB76B1AFD8ACB29FFD27F910D8DF5ADD153DE8F9
File Size: 2.76 MB, 2762752 bytes
Show More
MD5: 06cee5c727c6872f1c513ee223768ab6
SHA1: dada38b66ced5a24caacd9038ee63c1a874ebf5c
SHA256: 46C7F143BBCF1E8EB2FBE157831A76EC2FE98914A09206AC5EFBAB6FB324F848
File Size: 2.17 MB, 2167296 bytes
MD5: ec07a04f73181668f3007682c580669f
SHA1: 0c9c1d0caf0eddebb3697a90627fe4fb1a2ca238
SHA256: 3957BFA344534C1B2D9B4E1BA00F9EC64DA5B8F1587573A14EE6C96F9310D3DB
File Size: 2.52 MB, 2521600 bytes
MD5: d44352485911db97e3b1e01769ec9146
SHA1: 22509794b075f41631febf61abfac84c168215fe
SHA256: D76ECE3C6D25C8804B3D1B0AC6796314BE9D2600772B58007CE84766FAC4D619
File Size: 4.86 MB, 4860416 bytes
MD5: 9cf8097dfa65c0557018806ed0e9ba60
SHA1: a04346d7fa32855f0c61681966e4071a6d9080aa
SHA256: 2CAFE995516530C2DA301795CBD6645BD5661DCE230BC82E0A9626CA46EA5B7A
File Size: 4.36 MB, 4357120 bytes
MD5: 22fc47025341d001e437ae21f58faf91
SHA1: 0e354e8337f29f9016c310d6f30a60e53c932322
SHA256: 3C2E8F925B1F29CDC0FFEB9EF2B8C09AFF2AC989989E7A5C9EE100C18A2FEB70
File Size: 1.24 MB, 1236992 bytes
MD5: 4442c9f59b0155c3583952cd07eaa08d
SHA1: a1946a82885781444d24ea935659ab440bf3b362
SHA256: 764A661BA0F08E4FC5D1DEC669DA63D1E1276FC5D7131EB1EE05ABDCC0018CD4
File Size: 3.32 MB, 3316736 bytes
MD5: 0984df69262587918e304a860fc194bc
SHA1: 89b5097aaacb76d7db52763715d19ba25a039cae
SHA256: 3C5D4A2989C2398D71B08DA995D13513ED2D5FB792A4C179382AB00884FD6D0D
File Size: 1.04 MB, 1042944 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • 2+ executable sections
  • GetConsoleWindow
  • HighEntropy
  • imgui
  • No Version Info
  • ntdll
  • VirtualQueryEx
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 3,253
Potentially Malicious Blocks: 106
Whitelisted Blocks: 3,123
Unknown Blocks: 24

Visual Map

x x x x x x x x x 0 0 0 0 0 ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x ? 0 0 0 ? 0 x ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 0 x x x x x x x x 0 0 0 0 0 0 0 0 0 x x 0 0 x x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x 0 0 0 0 0 0 x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 1 x 0 0 0 0 0 0 0 0 0 1 0 0 0 x x x 0 x x x x x x x 0 0 0 0 x x x 0 0 x x x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 x x x x 0 x x x 0 x 0 x 0 x x x x x x x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.ZFBJ
  • Agent.ZFKD
  • CsgoInjector.FB
  • CsgoInjector.GH
  • Downloader.Agent.BAB
Show More
  • Downloader.Agent.BTF
  • Downloader.Agent.BTW
  • Gamehack.GACI
  • Gamehack.GAII
  • Gamehack.GYF
  • Gamehack.PSJ
  • Kryptik.EFI
  • Kryptik.EFL
  • Kryptik.ODFFC
  • TelegramHack.C
  • Trojan.Downloader.Gen.KB
  • Trojan.Kryptik.Gen.EHU

Files Modified

File Attributes
\device\namedpipe Generic Read,Write Attributes
\device\namedpipe Generic Write,Read Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateNamedPipeFile
  • ntdll.dll!NtCreateSection
Show More
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtFindAtom
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryWnfStateNameInformation
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUpdateWnfStateData
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Anti Debug
  • CheckRemoteDebuggerPresent
  • IsDebuggerPresent
  • OutputDebugString
Network Info Queried
  • GetAdaptersInfo
Network Winsock2
  • WSAStartup
Network Winsock
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • recvfrom
  • sendto
  • setsockopt
  • socket

Trending

Most Viewed

Loading...