Threat Database Trojans Trojan.Agent.Gen.AUA

Trojan.Agent.Gen.AUA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 5,735
Threat Level: 80 % (High)
Infected Computers: 30
First Seen: February 16, 2026
Last Seen: July 14, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.Gen.AUA on your system indicates a potential security threat that requires immediate attention. This Trojan-type threat can compromise your computer's security and put your personal data at risk. It is essential to understand the nature of this threat and take prompt action to remove it from your system.

What Is Trojan.Agent.Gen.AUA?

Trojan.Agent.Gen.AUA is a type of malware that can infect your computer without your knowledge or consent. The name "Trojan" refers to the fact that this malware can disguise itself as a legitimate program or file, allowing it to bypass your system's security defenses. The ".Gen" suffix suggests that this is a generic detection, indicating that the malware may not be a specific, well-known variant, but rather a broader category of threats.

How Trojan.Agent.Gen.AUA Operates

Once installed on your system, Trojan.Agent.Gen.AUA can operate in various ways, depending on its intended purpose. It may attempt to steal sensitive information, such as login credentials, credit card numbers, or personal data. It can also install additional malware, create backdoors for remote access, or disrupt your system's performance. In some cases, it may even recruit your computer into a botnet, allowing it to participate in distributed denial-of-service (DDoS) attacks or spam campaigns.

Symptoms of Infection

Identifying the symptoms of a Trojan.Agent.Gen.AUA infection can be challenging, as they may resemble issues caused by other malware or system problems. However, some common signs include slow system performance, frequent crashes, or unexpected pop-ups and advertisements. You may also notice unfamiliar programs or icons on your desktop, or experience unusual network activity. If you suspect that your system is infected, it is crucial to take immediate action to prevent further damage.

How to Remove Trojan.Agent.Gen.AUA

  1. Restart your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware components.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed without your consent.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform another scan with your anti-malware tool to ensure that all malware components have been removed.

Conclusion

Removing Trojan.Agent.Gen.AUA from your system requires a combination of technical expertise and caution. By following the steps outlined above and using reputable anti-malware tools, you can effectively eliminate this threat and protect your personal data. Remember to always be vigilant when downloading software or opening email attachments, and to keep your operating system and security software up to date to prevent future infections. If you are unsure about any aspect of the removal process, consider seeking guidance from a qualified IT professional or a reputable security expert.

Analysis Report

General information

Family Name: Trojan.Agent.Gen.AUA
Signature status: No Signature

Known Samples

MD5: 9b2708b87e7fe3c3469863f4b7028a67
SHA1: fa350b34459b7f34ecbe1ec227192d6856b6896b
SHA256: BB9AB0FDF35B80FB333CDDEF6F286F212B0011C6CFD432865C53CB79F13DB660
File Size: 794.11 KB, 794112 bytes
MD5: aa2daf93ca3660cd1366671c2f592324
SHA1: cb9a6a1286db7c6d1f11e8531ecc67fa52d2b892
SHA256: 047425BCFE5088E53176662E001D3CA0AAD6F0DF9BCBB1314208789AEC73E31F
File Size: 779.78 KB, 779776 bytes
MD5: cb09fae1ca16e2913522de2de7e992e1
SHA1: 50774b6c79c6800148a483e216ef82480c9a064d
SHA256: E6D50237C9F11989167A5C679A458D1A8FF7C9DF7D5A3EBF477CF2A4E181D474
File Size: 785.92 KB, 785920 bytes
MD5: e1b7f0cae129356de54c4bda133fc1f0
SHA1: 9e80c2d3d02928fc1b3c8e9c098efd147f7095ac
SHA256: D7BE29C55C965B41BC575C7E439DF0584E018F408B2B927D1A59ACB79845D39D
File Size: 784.38 KB, 784384 bytes
MD5: 73ce591e873038dcf0d28f416b3b09e1
SHA1: 2440cd3feead9363e85aba77efe621b86ab9a346
SHA256: 0F97B6A0C25560D63A863FF043A9556CB730ED6C8B20916EAC98E2B969AB5F48
File Size: 784.38 KB, 784384 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Company Name Session0Bypass
File Description Session0Bypass
File Version 1.0.0.0
Internal Name Session0Bypass.exe
Original Filename Session0Bypass.exe
Product Name Session0Bypass
Product Version 1.0.0

File Traits

  • fptable
  • No Version Info
  • x64

Block Information

Total Blocks: 1,769
Potentially Malicious Blocks: 378
Whitelisted Blocks: 1,391
Unknown Blocks: 0

Visual Map

x 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 0 0 0 0 x x x 0 x x 0 0 x x 0 0 0 x x 0 x x x 0 x 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 x 0 0 x x x 0 x x x x x 0 0 x x 0 0 x x x x x 0 x x x x x 0 0 x x 0 x x x x x x 0 x x x x x x 0 x x x x x x x 0 0 x x x x x 0 x x x x x x 0 x x x x 0 0 0 1 x x x x x x x x x x x 0 x 0 x x 0 x x x 0 x 0 0 x 0 x x 0 x x x x 0 x x 0 x x 0 x x 0 x x 0 x x 0 x x 0 x x 0 x x 0 x x x 0 0 x x x 0 x x 0 0 x 0 x 0 x x 0 x x x x 0 x x x x x x x x 0 x x x 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x x 0 x x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 x x x x 0 0 x 0 x 0 x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 x x x 0 x 0 x x x x x x x x x x x x x x x x 0 0 0 0 x x x x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x 0 x x 0 x x x x x x x x x x x x 0 0 x x x x 0 x 0 x x 0 0 0 0 0 x 0 0 0 0 x 0 x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x 0 0 x x x 0 0 x x x x 0 0 x x 0 x x x x 0 x x x x x x x 0 0 0 x x 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 x 0 x 0 x x x x x x x x x x x x x x x 0 0 0 x x x 0 x x x x x x 0 0 0 0 x x x x x x x x x 0 x 0 x x x x x 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 x x 0 0 0 x 0 0 x x x 0 0 0 0 0 x x x x x x x 0 x 0 0 x 0 0 x x x 0 0 x x 0 0 0 x 0 x x x x x x x x x x x x x x x x 0 0 0 x 0 x x x x x x x x x 0 x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 1 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\programdata\session0bypass\session0bypass.log Generic Write,Read Attributes
c:\users\public\s0b_384791e9b9e3.exe Generic Write,Read Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateResourceReserve
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcQueryInformationMessage
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
Show More
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges
Anti Debug
  • IsDebuggerPresent
Encryption Used
  • BCryptOpenAlgorithmProvider
Network Wininet
  • HttpOpenRequest
  • HttpQueryInfo
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
  • InternetSetOption
Network Winhttp
  • WinHttpOpen

Related Posts

Trending

Most Viewed

Loading...