Threat Database Trojans Trojan.Agent.DSS

Trojan.Agent.DSS

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 10,811
Threat Level: 80 % (High)
Infected Computers: 79
First Seen: January 24, 2025
Last Seen: July 20, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.DSS on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, potentially leading to unauthorized access, data theft, and other malicious activities. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Agent.DSS?

Trojan.Agent.DSS is a type of Trojan horse malware that can infiltrate your system without your knowledge or consent. The term "Trojan" refers to the fact that this malware disguises itself as a legitimate program or file, allowing it to bypass security measures and gain access to your system. The ".DSS" suffix may indicate a specific variant or subtype of the malware, but its exact meaning is not publicly known.

How Trojan.Agent.DSS Operates

Once installed, Trojan.Agent.DSS can operate in various ways, depending on its intended purpose. It may attempt to connect to a command and control server to receive instructions from its creators, allowing them to remotely control your system or steal sensitive information. It may also try to download and install additional malware or create backdoors to facilitate future attacks. The exact behavior of Trojan.Agent.DSS can vary, but its primary goal is to compromise your system's security and exploit its resources for malicious purposes.

Symptoms of Infection

The symptoms of a Trojan.Agent.DSS infection can be subtle, but they may include unusual system behavior, such as slow performance, unexpected crashes, or unfamiliar programs running in the background. You may also notice suspicious network activity, such as unexpected outgoing connections or data transfers. In some cases, the malware may attempt to disguise itself as a legitimate program or system process, making it difficult to detect without proper security tools.

  • Unexplained changes to system settings or configuration
  • Appearance of unfamiliar programs or icons
  • Increased system crashes or instability
  • Unusual network activity or data transfers

How to Remove Trojan.Agent.DSS

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a clean removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Agent.DSS from your system requires careful attention and a thorough approach. By following the steps outlined above and using reputable security tools, you can help ensure the complete removal of the malware and prevent future infections. It is essential to remain vigilant and proactive in maintaining your system's security, including keeping your operating system and software up to date, using strong antivirus protection, and avoiding suspicious downloads or attachments.

Analysis Report

General information

Family Name: Trojan.Agent.DSS
Signature status: No Signature

Known Samples

MD5: 21eb255ab06f1b5baf22d3d474ee4ee5
SHA1: 5ad3d8bb2f6d72766da1e8142c41a1b4d223e616
File Size: 7.66 MB, 7657984 bytes
MD5: 22748214a2f493a16411fca1b30b93c0
SHA1: feb638e6fae77c1255f2a11bf13fd68ee5741359
SHA256: 91E9D4F5608417604E2C1A897EC1AAB0369DC0F791883CDD566D7B5177E12051
File Size: 9.37 MB, 9370624 bytes
MD5: 69348f68bbeab9716449ae7c443736df
SHA1: db5c7f4c5a3ba9120983288405ed4da5929ae248
SHA256: CE07A6D9BCB0E60703DE86C053961279A3C05EC42CEFEC75BEB941DF69DFE460
File Size: 8.86 MB, 8864687 bytes
MD5: 186df1186d39914862bab6758763f273
SHA1: 73d935a5f2329e9e35992c0ece14ab18af1b7501
SHA256: 343D8DC211FD8C581BE882706896E56993776186C3ADD92E525E1C3A4F3693D0
File Size: 6.79 MB, 6794752 bytes
MD5: 7ffd579e708a6a8be0328c9da9930e9e
SHA1: 54c06312b964917a19083220d53c174e95c295bc
SHA256: 19D5203A441D2116F89F1342D0150A99F36D4D066F810CC130B3535F5FB4FC95
File Size: 4.11 MB, 4108800 bytes
Show More
MD5: e5394c14d8c4b2500e886543202e021e
SHA1: e45db5907c96e0826e64425ea78990702fa49843
SHA256: 9633546ECE8F4708B43F477FBE614DD256CFE84F5C8B7482680C1D66ED811B29
File Size: 9.86 MB, 9855832 bytes
MD5: 9b9d35b4f7839a7f982f3f5fdc7e6b3d
SHA1: 1ddf87c0c88ec3dc1cd2399d9c26a16872c1ba83
SHA256: DA657DC130E83332C349C8EC1CE9229018376B7A687A62FB633C87B4BACD5885
File Size: 5.80 MB, 5804032 bytes
MD5: 7ce7334dfbea424a4a083cded28261d4
SHA1: b88774eac4715e7314b67911712cdbd4a6d7d0e0
SHA256: ABA5C3E945F1CCB53035B2CC1A67918C9A1FAC1022FC4C69002B4F0DDC77A5F7
File Size: 4.11 MB, 4113920 bytes
MD5: 3a78c9e4d0f38a134cadd279c31c91da
SHA1: c738012740c23533d38e89f7ec88323943b6a5e1
SHA256: 7705BE593BA309E60BD41011D323C7FD2FF078816BA14B9171B0750AF8700407
File Size: 6.70 MB, 6697984 bytes
MD5: 69b988603f45f341c6903299513899e6
SHA1: e65e7929cbeed5a07422eea3d86be683dfd6a18f
SHA256: 55D1068A99AD7880930C0B066FB77F94A6C212FD7E8A42C83496539F15896E44
File Size: 7.44 MB, 7444480 bytes
MD5: 4d82d70ec5e797469a96dadb8a439ec9
SHA1: e228c7c853b114d1c912d6d35431dc99cc63c19b
SHA256: 721098A936BA0666489B35693B4C3A3C69F512353D7DD567F0D3F62E5F87366C
File Size: 5.60 MB, 5604864 bytes
MD5: da1c6bcc88835e45000fc2aa0bdad090
SHA1: 2e1ed98474dcf1316d9d1c9c5279baa05cd633b2
SHA256: 8CA5F24D71AB5FBAE39488C74E58AE9EEEEB102B24B4F257F14BBFB955D78609
File Size: 3.28 MB, 3281408 bytes
MD5: 9b5c4a4f61efb142363915aa7211d551
SHA1: aa53dc5fa387e50b38f3557c67394d3984eba7d4
SHA256: EF378655170E3BB7682FD75D859EAC76F14BB008D79191AAA4205149CA45A3DC
File Size: 7.01 MB, 7007744 bytes
MD5: c4d5223f2785b7cb7544d430fcfeed01
SHA1: 30b78375b16ffc0effb0ec872e5aff9b3599af9a
SHA256: 96E81009132DE154AEC4E522658DB965580D39731D1C2FF93E48FCE20BC00630
File Size: 2.92 MB, 2919936 bytes
MD5: ed919957c7aa8680971ca38b0f75f62c
SHA1: 3d89b869e4b70f4b38c9b832c3160e3bb9759716
SHA256: 69659CD7C4EF897ED0F75498132C721470A6E0CBD736F9D57606426A43D632CE
File Size: 5.61 MB, 5605888 bytes
MD5: cd0b2b80ada2213c3ff6da4adfba608d
SHA1: 9eea0574fe9e4be8ecfd3e1e7c9d66fb291d5630
SHA256: 558EB12875DE62F9EE9500E7D215942D586E8FF3DC1DB08C4DE60621274643D3
File Size: 9.66 MB, 9655296 bytes
MD5: 856442d52f2fe97599cc373c3774f653
SHA1: fe6981ff576b0e3429f6605cc71eab8661ee4f89
SHA256: 98A45A7A34CE5CD29BD7A64B99DD92ED599CEAFE3595DE00F4CC289AD8D52523
File Size: 7.28 MB, 7279616 bytes
MD5: 6135de83e7dbf059bc3ce86cbfb34061
SHA1: a18634a94db77f685b4bac1aa878cfe391fcb777
SHA256: 108C1234716CC0B756D2F0351B2B716AB56ACCBC6893C305B11BFCE0D9EF040D
File Size: 8.64 MB, 8641024 bytes
MD5: 037a3832e9ae7b1d37906a471cdcae9d
SHA1: f6c409f4b6587f409a2f306d22ffbd0427658577
SHA256: AA4ABA016F07178C4282122FECF26FDF6E4F1B8BC790DAFC8DFA362E46884D95
File Size: 6.94 MB, 6935040 bytes
MD5: f23e63cd82ee060416649cadb3a64e05
SHA1: fb6ebe3a01399ae63772318f6d8846122f4e6d2e
SHA256: C84838EDA2C469A42A1EC548D57505F6316373FFEAC4DBC06C11B1F79D9E3594
File Size: 8.89 MB, 8892416 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Show More

Windows PE Version Information

Name Value
Comments
  • 2018001
  • This installation was built with Inno Setup.
Company Name
  • AssinaNFeA3 - Emissão de notas fiscais v1.2.5, Inc.
  • Gera3 Sistemas
  • GRDJ Informática - Sistema Frest
  • Max Scalla Informática Ltda
  • Overcom Sistemas
File Description
  • ACBrNFSeX_Exemplo
  • AssinaNFeA3 Setup
  • Atualiza_Tabela_IBPT
  • Balanca
  • ConsultaCNPJ
  • fisUtil
  • GoComNFCe
  • MaxFIS
  • QuickTouch
File Version
  • 2022.0.0.2
  • 21.4.1.1
  • 15.0.0.0
  • 4.7.0.0
  • 4.0.37.0
  • 1.13.0.0
  • 1.4.2.201
  • 1.0.1.4
  • 1.0.0.0
  • 0.0.2.23
Internal Name
  • IBP
  • MaxFIS
Legal Copyright © 2017 by SoftDigi company. All rights reserved.
Original Filename Atualiza Tabela IBPT
Product Name
  • ACBrNFSeX_Exemplo
  • AssinaNFeA3
  • Atualiza_Tabela_IBPT
  • Balanca
  • ConsultaCNPJ
  • fisUtil
  • MaxFIS
  • QuickTouch
  • Serviço de Comunicação da NFCe
  • SoftDigi Easy GIF
Product Version
  • 21.4.1.1
  • 15.0.0.0
  • 4.6.0.0
  • 4.0.37.0
  • 1.13.0.0
  • 1.2.5
  • 1.0.1.4
  • 1.0.0.0
  • 1.0
Program I D
  • com.embarcadero.
  • com.embarcadero.Atualiza_Tabela_IBPT
  • com.embarcadero.Balanca
  • com.embarcadero.ConsultaCNPJ
  • com.embarcadero.fisUtil
  • com.embarcadero.GoComNFCe
  • com.embarcadero.MaxFIS
  • com.embarcadero.QuickTouch

Digital Signatures

Signer Root Status
FIRE SISTEMAS FIRE SISTEMAS Self Signed

File Traits

  • .adata
  • .aspack
  • 2+ executable sections
  • ASPack v2.12
  • HighEntropy
  • packed
  • VirtualQueryEx
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 17,633
Potentially Malicious Blocks: 50
Whitelisted Blocks: 13,939
Unknown Blocks: 3,644

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.DSS
  • Banload.XH
  • Banload.XJ
  • Casbaneiro.A
  • Danabot.DI
Show More
  • Delf.OF
  • Gamehack.ODB
  • Injector.JDA
  • Injector.XN
  • Ulise.BE
  • Vadokrist.B

Files Modified

File Attributes
c:\users\user\appdata\local\temp\is-83o4l.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-phlk7.tmp\db5c7f4c5a3ba9120983288405ed4da5929ae248_0008864687.tmp Generic Write,Read Attributes

Windows API Usage

Category API
Network Winsock2
  • WSAStartup
Other Suspicious
  • SetWindowsHookEx
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Keyboard Access
  • GetKeyState
Process Shell Execute
  • CreateProcess

Shell Command Execution

"C:\Users\Vnceliyl\AppData\Local\Temp\is-PHLK7.tmp\db5c7f4c5a3ba9120983288405ed4da5929ae248_0008864687.tmp" /SL5="$10272,8162602,721408,c:\users\user\downloads\db5c7f4c5a3ba9120983288405ed4da5929ae248_0008864687"