Threat Database Trojans Trojan.Agent.AID

Trojan.Agent.AID

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 22,370
Threat Level: 80 % (High)
Infected Computers: 9
First Seen: October 29, 2021
Last Seen: June 12, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.AID on your system indicates a potential security threat that requires immediate attention. This type of threat is known to compromise the integrity of your computer, putting your personal data and online security at risk. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Agent.AID?

Trojan.Agent.AID is a type of malware that can infiltrate your system through various means, such as exploited vulnerabilities, infected software downloads, or phishing attacks. The term "Trojan" refers to a type of malware that disguises itself as legitimate software, allowing it to evade detection and gain unauthorized access to your system. The ".Agent.AID" suffix suggests that this malware may be a variant of a known Trojan, but without further information, it is difficult to determine its exact origin or purpose.

How Trojan.Agent.AID Operates

Once installed, Trojan.Agent.AID can operate in various ways, depending on its intended purpose. It may attempt to communicate with its command and control servers to receive instructions or transmit stolen data. This malware can also install additional components, such as keyloggers, ransomware, or other types of malware, to further compromise your system. In some cases, Trojan.Agent.AID may modify system settings, create unauthorized accounts, or grant itself elevated privileges to maintain persistence and evade detection.

Symptoms of Infection

Identifying the symptoms of a Trojan.Agent.AID infection can be challenging, as this malware is designed to remain stealthy. However, some common indicators of infection include unusual system behavior, such as slow performance, frequent crashes, or unfamiliar programs running in the background. You may also notice suspicious network activity, altered system settings, or unfamiliar accounts on your system. If you suspect that your system is infected, it is crucial to take immediate action to contain and remove the threat.

How to Remove Trojan.Agent.AID

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for internet access. This will enable you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full system scan to detect and remove all instances of Trojan.Agent.AID.
  3. Uninstall any suspicious programs or applications that may be related to the infection. Be cautious when removing programs, as some may be legitimate or required by your system.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or plugins that may be associated with the infection.
  5. Reboot your system and perform a follow-up scan with your anti-malware tool to ensure that all instances of the malware have been removed.

Conclusion

Removing Trojan.Agent.AID from your system requires a combination of technical expertise and caution. By following the steps outlined above and using reputable removal tools, you can effectively eliminate this threat and prevent future infections. It is essential to remain vigilant and take proactive measures to protect your system, such as keeping your operating system and software up-to-date, using strong antivirus software, and avoiding suspicious downloads or links. By taking these precautions, you can significantly reduce the risk of infection and maintain a secure online environment.

Analysis Report

General information

Family Name: Trojan.Agent.AID
Signature status: No Signature

Known Samples

MD5: 93ea7f95e8583cbfbdaa65079d2f01c9
SHA1: 3c6b43315b8a1932881036e2c8ea10c22f729188
SHA256: 5E4CDBF1C4AD91948755B28306F7F1F89ADAB6F84E4099BCAFA08788773FC9CF
File Size: 139.26 KB, 139264 bytes
MD5: d1269e31489911b914af48bde78ea7c6
SHA1: eb6d271065a4a13908ff12dbfc67495f94c7f131
SHA256: A0C72BF0C1403557D81D7AC9F8FD7F79BFEF31C3C73FCFEF8F0989933829529B
File Size: 126.46 KB, 126464 bytes
MD5: 328142bc3252407c1bce07f04cd2ca0e
SHA1: 4ff913bb10d29d5063043c6f6b6d17692aac3664
SHA256: 593BE0063E3209580CA4CA6FCBD9A94F6B98EF221C3E8898620F6C50A7C5FC75
File Size: 918.53 KB, 918528 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description AppXor
File Version 1.0.0.0
Internal Name AppXor.exe
Legal Copyright Copyright © 2013
Original Filename AppXor.exe
Product Name AppXor
Product Version 1.0.0.0

File Traits

  • dll
  • x86

Block Information

Total Blocks: 81
Potentially Malicious Blocks: 11
Whitelisted Blocks: 70
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 x 0 0 0 0 x x 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Gamehack.JUA

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\3c6b43315b8a1932881036e2c8ea10c22f729188_0000139264.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\eb6d271065a4a13908ff12dbfc67495f94c7f131_0000126464.,LiQMAxHB

Trending

Most Viewed

Loading...