Threat Database Trojans TrojWare.Win32.Trojan.Agent.Gen

TrojWare.Win32.Trojan.Agent.Gen

By Domesticus in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 2,753
First Seen: November 28, 2011
Last Seen: December 19, 2025
OS(es) Affected: Windows

TrojWare.Win32.Trojan.Agent.Gen is a terrible Trojan that may be a component of fake anti-spyware or anti-virus programs. TrojWare.Win32.Trojan.Agent.Gen can use tricky tectics in an attempt to avoid detection of security tools. TrojWare.Win32.Trojan.Agent.Gen may also drop other malware infections. To protect your computer from harm, uninstall TrojWare.Win32.Trojan.Agent.Gen as soon as possible.

Aliases

15 security vendors flagged this file as malicious.

Antivirus Vendor Detection
AVG Downloader.Generic13.ASWM
AntiVir TR/Dldr.Dofoil.pyd.1
Kaspersky Trojan-Downloader.Win32.Dofoil.pyd
McAfee Artemis!18ECD4CE0C1D
AVG Generic32.CCJX
Fortinet W32/Tepfer.AAX!tr.pws
Ikarus Trojan.Win32.Inject
Sophos Mal/EncPk-AJS
Kaspersky Trojan-Spy.Win32.Zbot.kwsy
Avast Win32:Zbot-QYS [Trj]
McAfee PWS-Zbot-FAQD!19E11B038CA4
ClamAV Win.Trojan.Agent-215463
McAfee RDN/Generic.dx!nr
CAT-QuickHeal Trojan.Malagent
Fortinet W32/Agent.ARJ!tr.dldr

SpyHunter Detects & Remove TrojWare.Win32.Trojan.Agent.Gen

File System Details

TrojWare.Win32.Trojan.Agent.Gen may create the following file(s):
# File Name MD5 Detections
1. DisplaySwitch.exe 18ecd4ce0c1d8178adb90da83c3dbf96 51
2. temp.bin e3a1b69ffc4a9e01cee5a8c22cdc4d0b 33
3. cleamrt.exe 19e11b038ca4b1f29085d7bbd83c72f5 8
4. jdnpflie.exe 7dfd661766e2bf278c04315b22530639 5
5. KB954550-v5.com 350a8eac47a6550795e5dcaa8e954b48 4
6. SystemRoot.exe 1025cf87239a642b214aabe712ac32ff 4
7. KB6664577.exe 89292f3a601aaa4cbcf89bf99505c549 4
8. ebbbdaabcfafffad.exe f66994884c543ffe598a0594a2f200b3 4
9. MobileOptionPack.pif 2a30603237bfe6826464457badbf0aed 3
10. ~tmp5524176862780256284.exe 8fbc81d024f8b850ea1ab9ea976ca5b2 3
11. KB9293658.exe f25cb04d20053b70f0fe150db93ee98f 2
12. KB2779030.exe aa0e28d510932d18bb783fcd230d1213 2
13. lwrukjoav.exe 239ec7c5f4c322ddd14d5a00026022d7 2
14. WinSATAPI.exe c39bbe0fd20f11ff3c59fafbfa4c5441 2
15. ddfabaedaeeeebbad.exe 3ea821b9a1460034cec08deae203cd14 2
16. caP0uGMoKjg.exe d1bb5329b1dd5253cea472135e38a4da 2
17. dbebbfcad.exe 3ffef9b76d450e554238e624681e2a10 2
18. skskjbpjx.exe 30e1c054a5427c22a327fa2a37cd9c7b 2
19. hemxccape.exe f91553552a44c72458bb33232a239759 2
20. ttdasndku.exe 3fe0258f1ea7b5eabd8e656dd0023a1a 2
21. fafcfdaefad.exe 587deb42ed940a5593ddde570588ffa9 2
22. KB2583069.exe 1b67d261719c37d318632301175e3a3e 2
23. KB8949159.exe 55aa0b955c39efde14dd87ac3c441d1e 2
24. bedcdbcecceeaad.exe aed9cee4ea3b06dbf3cfc397b9e79a04 2
25. ~tmp337419347010106312.exe 143efc99daf7ea6377cc3dd518143a10 1
26. Tvtcwyhdewihgymj.exe b05fb84c2e34c0a3e98cc839b7e3ac42 1
27. C17E.exe 204744690ab96d6b8a0d050912708706 1
28. {132C4A06-1316-2911-0E24-0B041D0D1C2E}.exe 3b2c19223597af30616e05b78cba6c8c 1
29. KB2006109.exe 14f4ddbd43c23422159d48d0858d058c 1
More files

Analysis Report

General information

Family Name: Trojan.MewsSpy.A
Signature status: No Signature

Known Samples

MD5: 1fd800e8655baecfb5e633840d9e60b8
SHA1: f4767c50edc79e832cbd149fa3f719849b044b5a
SHA256: CA613D1C668AD3CBE99694D99A20C02590A1F5F0A89FD5232EFAAA76E489418F
File Size: 97.37 KB, 97374 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 32
Potentially Malicious Blocks: 29
Whitelisted Blocks: 3
Unknown Blocks: 0

Visual Map

x 0 x x x 0 x x 0 x x x x x x x x x x x x x x x x x x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MewsSpy.A

Trending

Most Viewed

Loading...