Threat Database Trojans Trojan.BadJoke.XA

Trojan.BadJoke.XA

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 4
First Seen: August 23, 2025
Last Seen: January 19, 2026
OS(es) Affected: Windows

The detection of Trojan.BadJoke.XA on your system indicates a potential security threat that requires immediate attention. This Trojan-type threat can compromise your computer's security and put your personal data at risk. It is essential to understand the nature of this threat and take prompt action to remove it from your system.

What Is Trojan.BadJoke.XA?

Trojan.BadJoke.XA is a type of malware that can infiltrate your system without your knowledge or consent. The name "Trojan" refers to the fact that this malware can disguise itself as a legitimate program or file, making it difficult to detect. The ".BadJoke.XA" part of the name is a designation used by security software to identify this specific threat. It is not necessarily related to a specific malware family, but rather a unique identifier for this particular strain of malware.

How Trojan.BadJoke.XA Operates

Trojan.BadJoke.XA, like other Trojans, can operate in various ways, depending on its intended purpose. It may be designed to steal sensitive information, such as login credentials or financial data, or to provide unauthorized access to your system. In some cases, it may also be used to install additional malware or to participate in botnet activities. The exact operation of Trojan.BadJoke.XA can vary, but its primary goal is to compromise your system's security and exploit its resources for malicious purposes.

Symptoms of Infection

The symptoms of a Trojan.BadJoke.XA infection can be subtle, making it challenging to detect. You may notice unusual system behavior, such as slow performance, unexpected crashes, or unfamiliar programs running in the background. In some cases, you may also receive suspicious alerts or notifications, or notice that your system is connecting to unknown servers or websites. If you suspect that your system has been infected with Trojan.BadJoke.XA, it is crucial to take immediate action to remove the threat.

How to Remove Trojan.BadJoke.XA

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of Trojan.BadJoke.XA.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.BadJoke.XA from your system requires a combination of technical expertise and caution. By following the steps outlined above and using reputable anti-malware tools, you can effectively remove this threat and restore your system's security. It is essential to remain vigilant and to take proactive measures to prevent future infections, such as keeping your operating system and software up to date, using strong passwords, and avoiding suspicious downloads or links. By taking these precautions, you can help protect your system and your personal data from the risks associated with Trojan.BadJoke.XA and other malware threats.

Analysis Report

General information

Family Name: Trojan.BadJoke.XA
Signature status: No Signature

Known Samples

MD5: 615d04a80c94f9e36efb9c567a8afc34
SHA1: cb3b158ce9b5a0eef3097c55c226e6084a4f4877
SHA256: 9F2C6D14A476D10615FE8E099EF8F87681B80382665B81C041EB5128AE7C7CB8
File Size: 466.43 KB, 466432 bytes
MD5: 899fabe6877fb5161207aa0efdb47c3c
SHA1: 6188fceca7630d20ce8d4465c48b76ce9e3354fb
SHA256: A7EB5D8DD57A540179EA000ADE82B862F76F14253423678A98E7976ABEDD2032
File Size: 264.70 KB, 264704 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Wither 5 Game
  • WobbyCorp (C) 2017
File Description
  • Magnesium Malware
  • Melt Your Screen
File Version
  • 4.5.1.7
  • 1.0.0.0
Internal Name
  • Magnesium.exe
  • ScreenMelter.exe
Legal Copyright
  • Copyright (C) 2022
  • Copyright WobbyCorp (C) 2017
Original Filename
  • Magnesium.exe
  • ScreenMelter.exe
Product Name
  • Magnesium
  • ScreenMelter
Product Version
  • 3.0.0.0
  • 0.0.0.0

File Traits

  • HighEntropy
  • ntdll
  • x86

Block Information

Total Blocks: 557
Potentially Malicious Blocks: 12
Whitelisted Blocks: 511
Unknown Blocks: 34

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? ? ? ? ? x ? ? x ? x x ? ? x x x x ? ? ? ? ? ? x ? ? x ? ? ? ? ? x x ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 2 0 0 0 0 1 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 1 1 1 1 1 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.HJDD
  • BadJoke.XA
  • Delf.SC
  • Injector.GEA

Files Modified

File Attributes
\device\harddisk0\dr0 Generic Read,Generic Execute,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 786496

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\control\crashcontrol::displayprereleasecolor ￿￿ RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\system::disabletaskmgr  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\system::disableregistrytools  RegNtPreCreateKey
HKCU\software\policies\microsoft\windows\system::disablecmd  RegNtPreCreateKey

Windows API Usage

Category API
Process Shell Execute
  • WinExec

Shell Command Execution

taskown /f %systemroot%system32 && taskown /f %userprofile% && icacls %systemroot%System32 /grant %username%:F && icacls %userprofile% /grant %username%:F

Related Posts

Trending

Most Viewed

Loading...