Threat Database Trojans Trojan.Agent.AIAB

Trojan.Agent.AIAB

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 2,626
First Seen: June 20, 2023
Last Seen: January 21, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.AIAB on your system indicates a potential security threat that requires immediate attention. This Trojan-type threat can compromise your computer's security and put your personal data at risk. It is essential to understand the nature of this threat and take prompt action to remove it from your system.

What Is Trojan.Agent.AIAB?

Trojan.Agent.AIAB is a type of malicious software that can infiltrate your computer without your knowledge or consent. The name "Trojan" refers to the fact that this malware disguises itself as a legitimate program or file, allowing it to evade detection and gain access to your system. Once inside, it can cause a range of problems, from stealing sensitive information to disrupting your computer's performance.

How Trojan.Agent.AIAB Operates

Trojan.Agent.AIAB operates by exploiting vulnerabilities in your system or tricking you into installing it. It can spread through various means, including infected email attachments, compromised websites, or infected software downloads. Once installed, it can communicate with its creators, allowing them to control your computer remotely and steal your personal data. This malware can also install additional malicious software, creating a network of infected computers that can be used for malicious purposes.

Symptoms of Infection

The symptoms of a Trojan.Agent.AIAB infection can vary, but common signs include slow computer performance, unexpected pop-ups or ads, and unfamiliar programs or icons on your desktop. You may also notice that your computer is crashing or freezing frequently, or that your personal data is being stolen or compromised. If you suspect that your computer is infected with Trojan.Agent.AIAB, it is crucial to take immediate action to remove it.

  • Unexplained changes to your computer's settings or configuration
  • Unfamiliar programs or icons on your desktop
  • Slow computer performance or frequent crashes
  • Unexpected pop-ups or ads
  • Stolen or compromised personal data

How to Remove Trojan.Agent.AIAB

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and run a full scan to detect and remove Trojan.Agent.AIAB.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and run another scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Agent.AIAB from your system requires prompt and careful action. By following the steps outlined above, you can help to ensure that your computer is free from this malicious software and that your personal data is protected. Remember to always be cautious when downloading software or opening email attachments, and to keep your anti-virus software up to date to prevent future infections. If you are unsure about any aspect of the removal process, consider seeking the help of a professional to ensure that your system is completely clean and secure.

Analysis Report

General information

Family Name: Trojan.Agent.AIAB
Signature status: No Signature

Known Samples

MD5: 74ec3eb57e776730d33132151ef5524e
SHA1: 4129967b45594dc6fee91fefb7b2e7c8792a250a
SHA256: 95A0429A1EC28B94606C02E4031B69058523496F15D02BB56267340A249FAC76
File Size: 1.32 MB, 1322040 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name CrystalDisk
File Description CrystalDiskInfo Setup
File Version 9.1.1.0
Internal Name CrystalDisk.exe
Legal Copyright Crystal Dew World
Original Filename Office.exe
Product Name CrystalDiskInfo 9.1.1
Product Version 9.1.1.0

File Traits

  • CryptUnprotectData
  • HighEntropy
  • Installer Version
  • No CryptProtectData
  • ntdll
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 3,642
Potentially Malicious Blocks: 1,002
Whitelisted Blocks: 2,428
Unknown Blocks: 212

Visual Map

0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 x x x 0 x x 0 0 x 0 x x x x 0 0 x x x x 0 0 0 0 x 0 0 x x x 0 x 0 0 x 0 0 x 0 0 x x x 0 0 0 0 x x x 0 0 x 0 x 0 x x x x x 0 0 0 x x x x 0 0 0 x 0 0 x 0 0 x 0 x x 0 0 0 0 0 ? ? ? 0 x ? ? ? ? 0 ? ? 0 ? x x ? x x x x x x x 0 x 0 x x x ? ? 0 x x x ? ? ? ? ? ? ? 0 0 0 0 0 0 ? x ? x ? x 0 0 x 0 0 x 0 x x ? x ? ? ? ? ? 0 x x x x x x ? ? 0 ? 0 ? 0 0 0 ? 0 ? 0 ? ? ? 0 x x ? ? x ? ? ? ? ? ? ? 0 x x x x ? 0 ? ? 0 0 x 0 x ? ? 0 0 ? ? ? ? ? ? ? ? ? x 0 0 x x ? 0 ? ? x 0 ? x ? 0 ? 0 ? ? ? ? ? ? 0 ? ? 0 0 0 ? ? x x ? ? 0 x x ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? 0 0 ? ? ? ? 0 0 0 0 x 0 0 0 ? x x ? ? 0 x x 0 ? 0 ? ? 0 ? ? ? x x x x x x x 0 x 0 ? 0 ? ? ? ? 0 0 0 x ? 0 ? x 0 ? ? ? ? 0 x x ? x x 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? x x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? x x x x ? ? ? x x 0 ? ? ? ? 0 ? 0 0 0 ? ? ? x x ? ? ? ? x x 0 0 x 0 0 x x ? 0 ? x 0 x ? ? x x 0 0 x ? x ? ? ? ? x ? x x ? ? ? ? ? ? 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 x x ? ? ? ? ? ? ? 0 0 ? ? ? ? ? 0 ? ? ? ? x 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? x x ? ? ? 0 0 0 0 x 0 0 0 0 x x 0 0 x 0 x 0 0 0 x x 0 0 0 x x 0 x 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? x 0 ? x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x ? x 0 0 0 0 0 0 0 x 0 x 0 0 0 x 0 0 x 0 0 0 0 0 x x x x x x x x x 0 x 0 x x 0 0 x x x x x x x x 0 x 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x x 0 x 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 x x 0 x 0 x x x x x x 0 x 0 0 x x x x x 0 x x x x x x x x x x x 0 x x x 0 0 0 x x 0 x x 0 x x 0 0 1 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x x 0 x x 0 x x 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 x x 0 x x x 0 ? x x x x x x 0 x x x 0 0 x x 0 0 0 x x x x x x x x 0 0 x x x x x x 0 0 0 0 x x 0 x 0 0 ? 0 0 0 0 0 0 0 0 x 0 x 0 x x 0 0 x 0 0 x 0 0 0 x 0 x x x x x x 0 x 0 0 x x x x x x x x 0 x 0 0 x 0 0 0 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x x 0 0 0 x x 0 0 0 x x 0 x x 0 0 ? ? 0 x x x x x ? x x x x 0 x x 0 x x x x x x x x x 0 x x x x x 0 x 0 0 0 0 x 0 x 0 0 0 x x 0 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x x x 0 x x 0 x 0 x 0 0 0 x x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 x 1 0 0 x x x x 0 x x 0 0 x x x x x 0 0 x x 0 x 0 x 0 x x 0 x 0 x 0 x 0 x x 0 x x x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x x 0 x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 x x x 0 x 0 1 0 x x x x x x x x 0 x 1 0 0 x 0 0 0 x 0 0 x x 0 0 x 0 0 0 x 0 0 x 0 0 x x x x 0 0 0 0 x 0 0 x x x x 0 x x x x x 0 0 x x 0 x 0 0 x 0 x 0 0 x x 0 x 0 x x x x x 0 0 x 0 x 0 x x 0 x x x x x x x 0 0 x x x x x x x x x x x x x x 0 x 0 0 x x x x x 0 x x x x x x 0 x 0 0 0 x x 0 x 0 0 x 0 x x 0 x x x x x x 0 x x x 0 x 0 0 0 x 0 0 x 0 0 x 0 x 0 x x x x x 0 x x x x 0 0 x x 0 x 0 x 0 0 x x x x 0 x x x x x x x x 0 x x x x x x x x x x x x x x x 0 x x x 0 x x x 0 x 0 x x 0 0 x 0 0 0 x 0 0 0 x x x x 0 0 x 0 x 0 x x 0 x x x 0 x x 0 x x 0 x x x 0 0 x 0 0 0 0 0 x 0 x x 0 0 0 0 1 0 x x x x x x x x x x x x x x x 0 x x x x x 0 0 x x 0 0 x 0 0 x x x 0 0 0 0 x 0 x x x 0 x 0 0 x x 0 0 0 0 x x x x x x x 0 x 0 0 0 x 0 x 0 x 0 x 0 x x 0 0 x x 0 x 0 x x 0 0 x x 0 0 0 0 x 0 x x x x x x x 0 0 x x 0 x x x 0 x 0 0 x x 0 x 0 0 0 x x x 0 0 0 x 0 0 x x 0 0 x x x x x 0 x 0 0 x 0 x x x 0 x x x 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 x x x 0 x x 0 0 x x 0 0 x x 0 x x 0 x 0 0 0 x 0 0 x 0 x 0 0 x 0 0 x 0 0 x 0 x x x x x x 0 x x x 0 x x x x x x x 0 x x x x x x x x x x 0 0 x 0 0 x x 0 x x x x 0 0 0 x x 0 x x 0 x x x 0 x x x x x 0 x 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.AIAF
  • Agent.AIAG

Files Modified

File Attributes
c:\users\user\appdata\local\maxloonafest131\maxloonafest131.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\fanbooster131\fanbooster131.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\run::maxloonafest131 C:\Users\Boihzors\AppData\Local\MaxLoonaFest131\MaxLoonaFest131.exe RegNtPreCreateKey

Trending

Most Viewed

Loading...