Threat Database Trojans Trojan.Agent.AIAK

Trojan.Agent.AIAK

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 16,699
Threat Level: 80 % (High)
Infected Computers: 8
First Seen: September 9, 2024
Last Seen: June 9, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.AIAK on your system indicates a potential security threat that requires immediate attention. This Trojan-type threat can compromise your computer's security and put your personal data at risk. It is essential to understand the nature of this threat and take prompt action to remove it from your system.

What Is Trojan.Agent.AIAK?

Trojan.Agent.AIAK is a type of malware that can infiltrate your computer without your knowledge or consent. The term "Trojan" refers to a type of malware that disguises itself as a legitimate program or file, allowing it to evade detection and gain access to your system. Once inside, it can cause a range of problems, from stealing sensitive information to disrupting your computer's performance.

How Trojan.Agent.AIAK Operates

Like other Trojan-type threats, Trojan.Agent.AIAK can operate in various ways, depending on its design and purpose. It may be used to steal personal data, such as login credentials, credit card numbers, or other sensitive information. It can also be used to install additional malware, create backdoors for remote access, or disrupt your computer's operation. The exact behavior of Trojan.Agent.AIAK can vary, but its presence on your system is a clear indication of a security breach.

Symptoms of Infection

Identifying the symptoms of a Trojan.Agent.AIAK infection can be challenging, as it may not always exhibit obvious signs of malware activity. However, you may notice unusual behavior, such as slow system performance, unexpected pop-ups or ads, or unfamiliar programs running in the background. You may also experience issues with your internet connection, such as frequent disconnections or redirects to suspicious websites. If you suspect that your system has been infected with Trojan.Agent.AIAK, it is crucial to take immediate action to remove the threat.

How to Remove Trojan.Agent.AIAK

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs associated with Trojan.Agent.AIAK.
  3. Uninstall any suspicious programs or applications that may be related to the infection. Be cautious when removing programs, as some may be legitimate or required for system operation.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons that may be associated with the infection.
  5. Reboot your computer and perform a follow-up scan with your anti-malware tool to ensure that the threat has been completely removed.

Conclusion

Removing Trojan.Agent.AIAK from your system requires a combination of technical knowledge and caution. By following the steps outlined above and using reputable anti-malware tools, you can effectively remove the threat and restore your system's security. It is essential to remain vigilant and take proactive measures to prevent future infections, such as keeping your operating system and software up to date, using strong antivirus protection, and avoiding suspicious downloads or email attachments. By taking these precautions, you can help protect your computer and personal data from the risks associated with Trojan.Agent.AIAK and other types of malware.

Analysis Report

General information

Family Name: Trojan.Agent.AIAK
Signature status: No Signature

Known Samples

MD5: 97f7e1a5cfbac1fc93a0827f8f11b845
SHA1: a3f9b080bfac7e99587b9d6548ca0c6291b6e53e
SHA256: 1F50C002332D89001FF9D8A1E6BA2EA985077DBC3370D0CCC8DC5D5E564A7D3E
File Size: 16.90 KB, 16896 bytes
MD5: a9a2cc3caa0ced58da2a67a75f4be13f
SHA1: 525bf1e56ab816bc73aaf64904dbfd865c368f63
SHA256: D5F9C94A3CF7DDD7458F3600204504176EF458A01AFF0BA089B65CA77FC1C65C
File Size: 11.26 KB, 11264 bytes
MD5: 81a25db472aadc7471747642e71741bd
SHA1: b64922d3412fff162eb71e9e9e7a023aad9fefff
SHA256: 37D97D6E64F5DC7B9CAF3144755EFBCC009926CAB1FD85A5DD0057E4FFF62785
File Size: 5.63 KB, 5632 bytes
MD5: 6566b51bcf2c9ae822fad77dd29a3020
SHA1: 6616a3d02b1b701ffc269f53c5018c027fe2c2d0
SHA256: A6C77FBB543684CA576174A4FC5E48830D965488404027728D2B77350D093262
File Size: 16.90 KB, 16896 bytes
MD5: 65239134e9e55171329bfffbf07ca1e2
SHA1: 46ad8fb3658d90ee222e3e6cdbf8815c6fc699d2
SHA256: E571AAC7D2A62D3AED532A13FE7D1DE8AC6F5A1621FA3D9F661D3C6F8315F624
File Size: 11.78 KB, 11776 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 0.0.0.0
File Version 0.0.0.0
Internal Name
  • build-uninstaller.exe
  • updater-uninstaller.exe
Original Filename
  • build-uninstaller.exe
  • updater-uninstaller.exe
Product Version 0.0.0.0

File Traits

  • No Version Info
  • x64

Block Information

Total Blocks: 17
Potentially Malicious Blocks: 15
Whitelisted Blocks: 2
Unknown Blocks: 0

Visual Map

x x x x x x 0 x x x x x x x x 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.AIAK
  • HEUR.MSIL.Generic_268221
  • Kryptik.GFDC

Files Modified

File Attributes
c:\users\user\appdata\local\temp\eyjjkjoz.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\qsmdsfca.exe Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 뷮㍧ᨭǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe �Ii���� RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
Show More
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Process Shell Execute
  • CreateProcess
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
  • VirtualAllocEx
Other Suspicious
  • AdjustTokenPrivileges
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Service Control
  • OpenSCManager
  • OpenService
Encryption Used
  • CryptAcquireContext

Shell Command Execution

C:\WINDOWS\System32\conhost.exe
C:\Users\Zynljiry\AppData\Local\Temp\QsMDSfCa.exe (NULL)
C:\Users\Rjlnbmis\AppData\Local\Temp\EYjjkJOZ.exe (NULL)

Trending

Most Viewed

Loading...