Trojan.Injector.XGA
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Popularity Rank: | 9,185 |
| Threat Level: | 80 % (High) |
| Infected Computers: | 74 |
| First Seen: | November 28, 2024 |
| Last Seen: | July 10, 2026 |
| OS(es) Affected: | Windows |
The detection of Trojan.Injector.XGA on your system indicates a potential security threat that requires immediate attention. This type of threat is generally associated with malicious software designed to infiltrate and compromise computer systems. Understanding the nature of this threat and taking appropriate steps to remove it is crucial to protecting your data and ensuring the security of your computer.
Table of Contents
What Is Trojan.Injector.XGA?
Trojan.Injector.XGA is identified as a Trojan-type threat, which typically means it is a type of malware that disguises itself as legitimate software. Trojans are known for their ability to grant unauthorized access to a computer system, allowing attackers to steal sensitive information, install additional malware, or use the infected computer for malicious activities. The name "Trojan.Injector.XGA" suggests it might have capabilities related to code injection, which could enable it to evade detection or hijack legitimate system processes.
How Trojan.Injector.XGA Operates
While specific details about how Trojan.Injector.XGA operates are not available, Trojans generally operate by deceiving users into installing them. This can happen through various means, such as downloading software from untrusted sources, opening malicious email attachments, or clicking on links to malicious websites. Once installed, a Trojan can create backdoors, allowing remote access to the infected computer. It can also modify system settings, disable security software, and install additional malware to further compromise the system.
Symptoms of Infection
Symptoms of a Trojan infection can vary widely but may include unusual system behavior, such as unexpected pop-ups, slow system performance, or frequent crashes. You might also notice that your antivirus software is disabled or that new, unfamiliar programs are installed on your computer. Sometimes, Trojans can operate silently, making them difficult to detect without proper security software. Regular system scans and monitoring for unusual activity are essential for early detection.
How to Remove Trojan.Injector.XGA
- Boot your computer in Safe Mode with Networking to limit the malware's ability to interfere with the removal process.
- Use a reputable anti-malware tool, such as SpyHunter, to perform a full system scan. This can help identify and remove the Trojan and any associated malware.
- Uninstall any recently installed programs that you do not recognize or that were installed around the time the Trojan was detected.
- Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings that the Trojan might have altered.
- Reboot your computer and perform another full system scan with your anti-malware tool to ensure that all components of the Trojan have been removed.
Conclusion
Removing Trojan.Injector.XGA and protecting your computer from future infections require a combination of using reputable security software, practicing safe computing habits, and regularly updating your operating system and applications. By understanding the risks associated with Trojans and taking proactive steps to secure your system, you can significantly reduce the likelihood of infection and protect your sensitive information from theft or damage. Always be cautious when downloading software or opening email attachments from unknown sources, and consider implementing additional security measures such as a firewall and anti-virus protection to safeguard your computer.
Analysis Report
General information
| Family Name: | Trojan.Injector.XGA |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
f03a0e704dd192a83f7040d5b5abeb04
SHA1:
5e0a7bd0cfad88c12e0bc8e40edb66fef1141ea3
SHA256:
E18DAB46E833181E602D25970380AF3B78F64465BBA3F85D48459BBC27AE0EDF
File Size:
91.65 KB, 91648 bytes
|
|
MD5:
d11ae0905796b4cb602299d133f9b915
SHA1:
826eeada56f9e813ce5ffbe135fdb72d4bcf61b0
SHA256:
A82A395182DB0C85BC8DB28F7CFD8E2AC70CD452751A4751FC47FA28A2833A8B
File Size:
90.62 KB, 90624 bytes
|
|
MD5:
02086955a56a20d793a0e71697604154
SHA1:
5a3db198affd77badac767614c652b99aaede4d2
SHA256:
9DE2B5451B12A6A89FD6C8265D0764186FCE4C5CF5B2ED99C85F224E497A0AE5
File Size:
280.06 KB, 280064 bytes
|
|
MD5:
bceff6faa9d8344509841d9776e6dc00
SHA1:
337fc13915a0eaadbb7254d409f25b75fc52f9d9
SHA256:
B78FCC0CFE774E6E793856DBBBD5E45E57EDA66F745E19DE2EB730472303903A
File Size:
253.44 KB, 253440 bytes
|
|
MD5:
e0ceeb2854cb5299091c54cbfda4562f
SHA1:
0f70729fd7bd38dd5d1ceda83389ce03d8d65446
SHA256:
630689C830D36E403367ABE3EA01D255566946FBFCFAB7339A3BF0057604C86C
File Size:
98.82 KB, 98816 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have security information
- File has TLS information
- File is 32-bit executable
- File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
Show More
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Company Name |
|
| File Description |
|
| File Version |
|
| Legal Copyright |
|
| Product Name |
|
| Product Version |
|
File Traits
- 2+ executable sections
- No Version Info
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 495 |
|---|---|
| Potentially Malicious Blocks: | 1 |
| Whitelisted Blocks: | 494 |
| Unknown Blocks: | 0 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Trojan.Downloader.Gen.GF
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| \device\namedpipe | Generic Read,Write Attributes |
| \device\namedpipe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\1011ef3.bat | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\1011ef3.bat | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\5267cf7.bat | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\5267cf7.bat | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\544f43a.bat | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\544f43a.bat | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\6088d5a.bat | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\6088d5a.bat | Synchronize,Write Attributes |
Show More
| c:\users\user\appdata\local\temp\711b878.bat | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\711b878.bat | Synchronize,Write Attributes |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\software\wow6432node\microsoft\rfc1156agent\currentversion\parameters::trappolltimemillisecs | 㪘 | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 䠡鈙ǜ | RegNtPreCreateKey |
| HKCU\software\photoupz::string3 | Giveawayoftheday | RegNtPreCreateKey |
| HKCU\software\photoupz::string5 | ����λ�̽ƺ��� | RegNtPreCreateKey |
| HKCU\local settings\muicache\1b\52c64b7e::@c:\windows\system32\ndfapi.dll,-40001 | Windows Network Diagnostics | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Process Shell Execute |
|
| Syscall Use |
Show More
63 additional items are not displayed above. |
| Anti Debug |
|
| User Data Access |
|
| Process Terminate |
|
| Process Manipulation Evasion |
|
| Network Winsock2 |
|
| Other Suspicious |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
cmd.exe /c ""C:\Users\Qqpvwgzw\AppData\Local\Temp\6088D5A.bat" "c:\users\user\downloads\5e0a7bd0cfad88c12e0bc8e40edb66fef1141ea3_0000091648""
|
WriteConsole:
|
WriteConsole: c:\users\user\do
|
WriteConsole: IF
|
WriteConsole: EXIST "C:\Progra
|
Show More
WriteConsole: (
|
WriteConsole: Copy
|
WriteConsole: "c:\Users\user\
|
WriteConsole: )
|
WriteConsole: Else
|
WriteConsole: (
|
WriteConsole: Copy
|
WriteConsole: "c:\Users\user\
|
WriteConsole: )
|
WriteConsole:
|
WriteConsole: The system canno
|
WriteConsole:
|
WriteConsole: c:\users\user\do
|
WriteConsole: taskkill
|
WriteConsole: /F /IM drwebscd
|
WriteConsole:
|
C:\WINDOWS\system32\taskkill.exe taskkill /F /IM drwebscd.exe
|
WriteConsole: ERROR: CoInitial
|
WriteConsole:
|
WriteConsole: c:\users\user\do
|
WriteConsole: regsvr32.exe
|
WriteConsole: /u /s "c:\Users
|
WriteConsole:
|
C:\WINDOWS\system32\regsvr32.exe regsvr32.exe /u /s "c:\Users\user\downloads\\program files\DrWeb\drwsxtn.dll"
|
WriteConsole:
|
WriteConsole: c:\users\user\do
|
WriteConsole: "program files\n
|
WriteConsole: regdelkey "HKLM
|
WriteConsole:
|
WriteConsole: The system canno
|
WriteConsole:
|
WriteConsole: c:\users\user\do
|
WriteConsole: "program files\n
|
WriteConsole: regdelkey "HKLM
|
WriteConsole:
|
WriteConsole: The system canno
|
WriteConsole:
|
WriteConsole: c:\users\user\do
|
WriteConsole: "program files\n
|
WriteConsole: regdelkey "HKLM
|
WriteConsole:
|
WriteConsole: The system canno
|
WriteConsole:
|
WriteConsole: c:\users\user\do
|
WriteConsole: "program files\n
|
WriteConsole: regdelkey "HKLM
|
WriteConsole:
|
WriteConsole: The system canno
|
WriteConsole:
|
WriteConsole: c:\users\user\do
|
WriteConsole: "program files\n
|
WriteConsole: regdelval "HKLM
|
WriteConsole:
|
WriteConsole: The system canno
|
WriteConsole:
|
WriteConsole: c:\users\user\do
|
WriteConsole: "program files\n
|
WriteConsole: regdelkey "HKLM
|
WriteConsole:
|
WriteConsole: The system canno
|
WriteConsole:
|
WriteConsole: c:\users\user\do
|
WriteConsole: "program files\n
|
WriteConsole: regdelkey "HKLM
|
WriteConsole:
|
WriteConsole: The system canno
|
WriteConsole:
|
WriteConsole: c:\users\user\do
|
WriteConsole: "program files\n
|
WriteConsole: regdelkey "HKLM
|
WriteConsole:
|
WriteConsole: The system canno
|
WriteConsole:
|
WriteConsole: c:\users\user\do
|
WriteConsole: "program files\n
|
WriteConsole: regdelkey "HKCU
|
WriteConsole:
|
WriteConsole: The system canno
|
WriteConsole:
|
WriteConsole: c:\users\user\do
|
WriteConsole: "program files\n
|
WriteConsole: regdelval "HKLM
|
WriteConsole:
|
WriteConsole: The system canno
|
WriteConsole:
|
WriteConsole: c:\users\user\do
|
WriteConsole: "program files\n
|
WriteConsole: execmd del "~$f
|
WriteConsole:
|
WriteConsole: The system canno
|
WriteConsole:
|
WriteConsole: c:\users\user\do
|
WriteConsole: "program files\d
|
WriteConsole: /remove
|
WriteConsole:
|
WriteConsole: The system canno
|
cmd.exe /c ""C:\Users\Skltzijt\AppData\Local\Temp\544F43A.bat" "c:\users\user\downloads\826eeada56f9e813ce5ffbe135fdb72d4bcf61b0_0000090624""
|
C:\WINDOWS\system32\net.exe net use Z: /persistent:yes \\accserver\account
|
WriteConsole: Access is denied
|
WriteConsole: 'expressi' is no
|
C:\WINDOWS\system32\net.exe net use Z: /delete
|
cmd.exe /c ""C:\Users\Rkgzqghz\AppData\Local\Temp\5267CF7.bat" "c:\users\user\downloads\5a3db198affd77badac767614c652b99aaede4d2_0000280064""
|
C:\WINDOWS\system32\NETSTAT.EXE netstat -ano
|
C:\WINDOWS\system32\findstr.exe findstr "5037"
|
cmd.exe /c ""C:\Users\Ytunurbm\AppData\Local\Temp\711B878.BAT" "c:\users\user\downloads\337fc13915a0eaadbb7254d409f25b75fc52f9d9_0000253440""
|
cmd.exe /c ""C:\Users\Ykqkruqi\AppData\Local\Temp\1011EF3.bat" "c:\users\user\downloads\0f70729fd7bd38dd5d1ceda83389ce03d8d65446_0000098816""
|
WriteConsole: reg
|
WriteConsole: add "HKCU\Softw
|
C:\WINDOWS\system32\reg.exe reg add "HKCU\Software\Photoupz" /f /v "String3" /t REG_SZ /d "Giveawayoftheday"
|
WriteConsole: The operation co
|
C:\WINDOWS\system32\reg.exe reg add "HKCU\Software\Photoupz" /f /v "String5" /t REG_SZ /d "CFCFC9C7CEBBCFCCBDC6BABEBECB"
|
WriteConsole: start
|
WriteConsole: PhotoUpz.exe
|