Threat Database Trojans Trojan.Agent.FD

Trojan.Agent.FD

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 154
First Seen: June 2, 2021
Last Seen: February 16, 2024
OS(es) Affected: Windows

The detection of Trojan.Agent.FD on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to understand its nature and how to remove it effectively.

What Is Trojan.Agent.FD?

Trojan.Agent.FD is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate or harmless. The name "Trojan" refers to the malware's ability to infiltrate a system by masquerading as something else, much like the legendary Trojan Horse of ancient Greece. Trojan horses can be used to install additional malware, steal sensitive information, or provide unauthorized access to the infected system.

How Trojan.Agent.FD Operates

Once installed, Trojan.Agent.FD can operate in various ways, depending on its intended purpose. It may attempt to connect to remote servers to download additional malware or receive instructions from its creators. It can also try to gather sensitive information, such as login credentials, credit card numbers, or other personal data. In some cases, Trojan horses can create backdoors, allowing hackers to access the infected system remotely and perform malicious activities.

Symptoms of Infection

The symptoms of a Trojan.Agent.FD infection can vary, but common signs include slow system performance, frequent crashes, and unusual network activity. You may also notice unfamiliar programs or icons on your desktop, or receive unexpected pop-ups and alerts. In some cases, the malware may attempt to disable security software or prevent you from accessing certain system settings.

  • Unexplained changes to system settings or configuration
  • Increased CPU usage or memory consumption
  • Unfamiliar programs or processes running in the background
  • Difficulty accessing certain system features or settings

How to Remove Trojan.Agent.FD

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any associated malware
  3. Uninstall any suspicious programs or applications that may be related to the infection
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that the malware has been completely removed

Conclusion

Removing Trojan.Agent.FD from your system requires careful attention to detail and a thorough understanding of the malware's behavior. By following the steps outlined above and using reputable security software, you can effectively remove the malware and prevent future infections. It's essential to remain vigilant and proactive in maintaining your system's security, as new threats emerge daily. Regularly updating your operating system, software, and security tools can help prevent similar infections in the future.

Analysis Report

General information

Family Name: Trojan.Agent.FD
Signature status: No Signature

Known Samples

MD5: 6e4b30c97eee185f5774f65b67a46196
SHA1: e750a8087fc0a3e54a5cc31988454c0fcb57b87e
File Size: 1.01 MB, 1005568 bytes
MD5: 7ea5b303ed079b27f0b1503c390a6e40
SHA1: b4c39960b669edac37565196a41529954653def8
File Size: 2.18 MB, 2179072 bytes
MD5: 7883b49bf1ab0dcb135c37da2beb36a5
SHA1: e7d569eac29a95870ced46540de92428000d7add
SHA256: D4A694DF3F7883ACFF4FFECD515001EC81C95628AE0942D7D6234B7B98C7AB08
File Size: 4.86 MB, 4863488 bytes
MD5: 75645d8c08fc5cb21946225d52939f16
SHA1: 5e17494400a767d0f0a896e4108e36f521f04fb7
SHA256: FDC228794AFE7BFCFF2A839ED72C2C858DB3378F6673DF2DD3AD16A52A242B7C
File Size: 4.61 MB, 4608000 bytes
MD5: bb911cbb2b624b745d1c6933a6f69b8a
SHA1: aacfb35549c9f6b4ede5e107386df6eb98895c69
SHA256: 3400EFB9736FEFDA0401E698909A18D7A01660CA78CA9E16062468703C25FBD9
File Size: 5.51 MB, 5510632 bytes
Show More
MD5: d3e847785613a706c4533b19c3eeb7fe
SHA1: 5ec8afd329159b327135c649e4cb1d81e168e116
SHA256: 2F6591C093C6DC568EA11602F01F557CDB6F85E87256698E84BCB3E773BBE554
File Size: 5.64 MB, 5641616 bytes
MD5: b698ecefdf3bfb57250579b2fda8cd1e
SHA1: 7b596225c2f1bc7315ca4892eb33f42bb858f2a1
SHA256: 081870543772D0CD1A25DA6CFF67CD6945BEB7441A4FD5172EBA8FE481FCA90C
File Size: 5.32 MB, 5318144 bytes
MD5: a5d4998edad2b52f39caa393dc2b4110
SHA1: c9bdd6a5ce392555c0181443273b13f6ff5ddf7e
SHA256: C85A4CD379994BA2B8AC15DD24B2085F0D0E4CC032E5BB47346D3392664AC586
File Size: 9.24 MB, 9238016 bytes
MD5: 7ecf4cb4a6afa1ee1e72f65661bdb442
SHA1: 9bc522f2eab521d0ac65a6510920539188867004
SHA256: 50F787FA91E64B38B43BE2F8311A344FFC3AC2C246ECAEE0ED04DF80A96E3CB8
File Size: 3.16 MB, 3155456 bytes
MD5: 7f97003e76bc43b6be4c206468e18cb7
SHA1: 4a466c77f8332e5c7422c2c23ca47d809fe5e32f
SHA256: 583273CCC58C483544522456B9BDEAC2570918F5CEA214E6A084077421801449
File Size: 6.91 MB, 6909158 bytes
MD5: 525c9ab2f145fa0396164dca9b8f45d2
SHA1: 3f641f08431b47467dd5eed50dfb36c48454b676
SHA256: DB27C37F2ED9E8F8104AAEF40EA5DB5545944E81E4F7767CB7AFE2E062618CD0
File Size: 1.25 MB, 1248814 bytes
MD5: a3b26cd44a5e28fca822c0ceff5e3217
SHA1: f48cf2a4fea0bb938b0edbbbefbd0cfa313e7ffb
SHA256: D39945FE1588A8A72A5C97E08F2FE268A55CC25789F1E6ED7A575EC70CA1151A
File Size: 6.97 MB, 6972928 bytes
MD5: 827a0f85b07247d0eae6fb5d47c3baba
SHA1: ed777911ba207c633d5d3865889928474247f42e
SHA256: DE277A3170ED64210090343A2B597AA112BEDDD1EFCF3A66A81C10EDE9251397
File Size: 6.07 MB, 6071808 bytes
MD5: 4e7145f80c91c1354940062e2443317d
SHA1: b9340c625a3d3588a112bb8a206cca5f81833342
SHA256: 426D25E0AAEFCBFD8128972F17C228ACABC062DFE2F49E03C567C47E8A679221
File Size: 8.00 MB, 8002048 bytes
MD5: 93d5d18ec4533e3ce8c86f648b1beae8
SHA1: edbb17f957257dc182e0de99e2c5de5a1def1bf5
SHA256: 58DABA47B6EAD5717612CF425E27D2B75C5FDA0F0BDE59156B4FA4575D42074F
File Size: 4.92 MB, 4919072 bytes
MD5: ae0558154b86968f4499555ddae4d059
SHA1: d8950d562f6c87562d94898d1461be449b8088cb
SHA256: C681F46E6496D33F87005E0C55C4564028E2D7FE81D61F04203DC171E0126BE4
File Size: 2.33 MB, 2328672 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
Show More
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 1.2.7.90
  • 1.0.0.35841
  • 1.0.0.1
  • 1.0.0.0
Comments 64th Services
Company Name
  • 64th spoffer & cheat
  • CPUID
  • EFD Software
  • JK KiNG
  • Microsoft
  • OS-Z
  • The NW.js Community
  • TMT MEDIATEK UNIVERSAL V3
Company Short Name nwjs.io
File Description
  • 64th Services
  • CPU-Z Application
  • HD Tune
  • JK KiNG Xbox to PS4 Controller
  • nwjs
  • OpenBullet
  • OS-Z
  • SFVipPlayer
  • t.me/acgbuster
  • Telegram@dohnaduona
Show More
  • TMT MEDIATEK UNIVERSAL V3
File Version
  • 6.0.0.0
  • 2, 0, 4, 0
  • 1.2.7.90
  • 1.00
  • 1.0.1
  • 1.0.0.35841
  • 1.0.0.0
  • 0.48.4
Internal Name
  • 64th Services.exe
  • cpuz.exe
  • HD Tune.exe
  • JK KiNG Xbox to PS4.dll
  • nw_exe
  • OpenBullet.exe
  • OS-Z.dll
  • SFVipPlayer.exe
  • TJprojMain
  • TMT MEDIATEK UNIVERSAL V3.dll
Show More
  • Win
Last Change ac9418ba9c3bd7f6baaffa0b055dfe147e0f8364-refs/branch-heads/3538@{#468}
Legal Copyright
  • (c) EFD Software. All rights reserved.
  • Copyright (C) 2004-2023
  • Copyright 2020, The NW.js community and The Chromium Authors. All rights reserved.
  • Copyright 2025 Google LLC. All rights reserved.
  • Copyright © 2018
  • Copyright © 2024
  • Copyright © 2024
  • Copyright © salezli 2024
Original Filename
  • 64th Services.exe
  • cpuz.exe
  • HD Tune.exe
  • JK KiNG Xbox to PS4.dll
  • nw.exe
  • OpenBullet.exe
  • OS-Z.dll
  • SFVipPlayer.exe
  • TJprojMain.exe
  • TMT MEDIATEK UNIVERSAL V3.dll
Show More
  • Win.exe
Product Name
  • 64th Services
  • CPU-Z Application
  • HD Tune
  • JK KiNG Xbox to PS4 Controller
  • nwjs
  • OpenBullet
  • OS-Z
  • Project1
  • SFVipPlayer
  • TMT MEDIATEK UNIVERSAL V3
Show More
  • Win
Product Short Name nwjs
Product Version
  • 6.0.0.0
  • 2, 0, 4, 0
  • 1.2.7.90
  • 1.00
  • 1.0.1
  • 1.0.0.0
  • 1.0.0
  • 0.48.4

Digital Signatures

Signer Root Status
Google LLC DigiCert Trusted Root G4 Hash Mismatch
OpenBullet Anomaly OpenBullet Anomaly Hash Mismatch
serbianforum.org serbianforum.org Hash Mismatch

File Traits

  • 2+ executable sections
  • Enigma
  • HighEntropy
  • No Version Info
  • ntdll
  • vmp section variant
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 3,975
Potentially Malicious Blocks: 4
Whitelisted Blocks: 3,968
Unknown Blocks: 3

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.FD
  • Agent.HJD
  • Bitcoinminer.FDO
  • ClipBanker.HBA

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetProcessWindowStation
  • win32u.dll!NtUserGetThreadState
User Data Access
  • GetUserObjectInformation
Other Suspicious
  • SetWindowsHookEx