Threat Database Trojans Trojan.PSW.Agent.FBA

Trojan.PSW.Agent.FBA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 13,869
Threat Level: 80 % (High)
Infected Computers: 9
First Seen: January 13, 2026
Last Seen: July 7, 2026
OS(es) Affected: Windows

The detection of Trojan.PSW.Agent.FBA on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise your computer's security and steal sensitive information, making it essential to understand its nature and take prompt action to remove it.

What Is Trojan.PSW.Agent.FBA?

Trojan.PSW.Agent.FBA is a type of Trojan horse malware that is designed to infiltrate your system without your knowledge or consent. The name "Trojan" refers to the fact that this malware disguises itself as a legitimate program or file, allowing it to bypass your system's security defenses. The ".PSW.Agent.FBA" part of the name suggests that this malware may be focused on stealing passwords or other sensitive information.

How Trojan.PSW.Agent.FBA Operates

Once Trojan.PSW.Agent.FBA has infected your system, it can operate in various ways to achieve its malicious goals. It may create backdoors that allow remote access to your system, steal sensitive information such as login credentials or financial data, or install additional malware to further compromise your system. This malware can also modify system settings, disable security software, or exploit vulnerabilities in your system to maintain its presence and carry out its malicious activities.

Symptoms of Infection

Identifying the symptoms of a Trojan.PSW.Agent.FBA infection can be challenging, as this malware is designed to operate stealthily. However, you may notice unusual system behavior, such as slow performance, frequent crashes, or unfamiliar programs running in the background. You may also receive unexpected pop-ups, experience unusual network activity, or find that your system settings have been changed without your consent. If you suspect that your system has been infected with Trojan.PSW.Agent.FBA, it is crucial to take immediate action to remove the malware and prevent further damage.

How to Remove Trojan.PSW.Agent.FBA

  1. Restart your system in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs associated with Trojan.PSW.Agent.FBA.
  3. Uninstall any suspicious programs or applications that may be related to the malware infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons that may have been installed by the malware.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.PSW.Agent.FBA from your system requires careful attention to detail and a thorough understanding of the malware's nature and behavior. By following the steps outlined above and using reputable anti-malware tools, you can effectively remove this malware and prevent further damage to your system. It is also essential to maintain good security practices, such as regularly updating your operating system and software, using strong passwords, and being cautious when opening email attachments or clicking on links from unknown sources, to prevent future malware infections.

Analysis Report

General information

Family Name: Trojan.PSW.Agent.FBA
Signature status: No Signature

Known Samples

MD5: cc11f4cc1678dec5bd7cd18a5789f2d8
SHA1: d695f04fd0e8a16e9666d1570022374490604503
SHA256: 20758EBD0753B1425F0C5E71DCD9611FE1D88EDE4916D8F0AC4AE60397DC70E9
File Size: 1.49 MB, 1486336 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • fptable
  • HighEntropy
  • No Version Info
  • x64

Block Information

Total Blocks: 1,172
Potentially Malicious Blocks: 78
Whitelisted Blocks: 1,041
Unknown Blocks: 53

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? x x x x x 0 0 0 0 0 x 0 0 ? ? ? x ? ? ? ? ? ? ? 0 ? ? ? 0 0 ? 0 0 0 0 x 0 0 x 0 0 0 x 0 x ? 0 x 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 x 0 0 x 0 0 0 0 0 x x x x x x x 0 x x 0 x 0 0 ? 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 0 0 0 x 0 0 0 0 0 x 0 0 ? ? ? 0 x x 0 x ? ? ? x x ? 0 x ? 0 x x x x x ? 0 0 x ? 0 ? 0 ? x ? 0 0 ? ? x 0 ? x 0 0 x 0 0 0 x 0 0 0 x x 0 x x x 0 ? ? x ? ? ? ? ? ? ? ? ? 0 0 x 0 0 x x 0 x x x x 0 0 0 ? ? x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 1 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • EDRFreeze.A

Files Modified

File Attributes
\device\namedpipe\msedge.sync.55984.2605 Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (NULL)

Related Posts

Trending

Most Viewed

Loading...