Threat Database Trojans Trojan.Agent.GSA

Trojan.Agent.GSA

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 17
First Seen: April 9, 2025
Last Seen: April 15, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.GSA on your system indicates a potential security threat that requires immediate attention. This type of threat is categorized as a Trojan, which is a broad term for malicious software that can cause harm to your computer or steal sensitive information. In this report, we will provide an overview of what Trojan.Agent.GSA is, how it operates, the symptoms of infection, and most importantly, the steps you can take to remove it from your system.

What Is Trojan.Agent.GSA?

Trojan.Agent.GSA is a type of malware that can infect your computer without your knowledge or consent. The term "Trojan" refers to the fact that this type of malware often disguises itself as legitimate software, allowing it to bypass security measures and gain access to your system. Once inside, it can perform a variety of malicious activities, including data theft, system compromise, and the installation of additional malware.

How Trojan.Agent.GSA Operates

The exact operation of Trojan.Agent.GSA can vary, but like other Trojans, it typically relies on deception and exploitation of vulnerabilities to infect a system. It may spread through email attachments, infected software downloads, or by exploiting weaknesses in operating systems or applications. Once installed, it can communicate with its creators, allowing them to control the infected system remotely, steal sensitive information, or use the system for malicious purposes such as spamming or distributing malware.

Symptoms of Infection

The symptoms of a Trojan.Agent.GSA infection can be subtle and may not always be immediately apparent. However, common signs include unusual system behavior, such as unexpected pop-ups, slow system performance, and unfamiliar programs or icons on your desktop. You might also notice that your browser homepage has changed, or you are being redirected to unwanted websites. In some cases, the infection might lead to more severe issues, such as data loss or system crashes.

How to Remove Trojan.Agent.GSA

Removing Trojan.Agent.GSA requires careful steps to ensure that the malware is completely eradicated from your system. Here is a step-by-step guide to help you through the removal process:

  1. Boot your computer in Safe Mode with Networking. This will prevent the malware from loading and give you a cleaner environment to work in.
  2. Download and install a reputable anti-malware tool, such as SpyHunter. Perform a full scan of your system to detect and remove all traces of the malware.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time the malware was detected.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings. This can help remove any malicious extensions or settings that the malware may have installed.
  5. Reboot your computer and perform another scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

The detection and removal of Trojan.Agent.GSA are critical steps in protecting your computer and personal data from potential harm. By understanding what this threat is, how it operates, and the symptoms of infection, you can take proactive measures to secure your system. Following the removal steps outlined above can help ensure that your computer is free from this malware. Remember, prevention is key; keeping your operating system, software, and security tools up to date, along with practicing safe computing habits, can significantly reduce the risk of future infections.

Analysis Report

General information

Family Name: Trojan.Agent.GSA
Signature status: No Signature

Known Samples

MD5: f29fe4e1486d758fbc41d4ea6d25bc73
SHA1: 9699becbf35802b08fdcf0ada427fa8cdd24dc57
SHA256: B10057B8DE25295E30894C2EC8345CCD30C2631139C81A5DC2536E9275203B45
File Size: 566.78 KB, 566784 bytes
MD5: 96521da287cc9ebf1af8d7811c0310d7
SHA1: ba7458a9b2e79ba19fad0cac4b72c66fcc40c58c
SHA256: 50C1EAF90C78785E362C798BE737956C3BBEBF38C52D9D60F9955F074E266986
File Size: 566.78 KB, 566784 bytes
MD5: 886077b618bfdc78c1eb6e8aae7806fa
SHA1: 3d65167b7183866e7389b30bbeaaddbd5392e9a5
SHA256: 53784FED3CAD84B04E8FAF9742E9C0283F7FA814C0886F2DD808D96405A748F5
File Size: 566.27 KB, 566272 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
All Names VideoRender
Build Date
  • 24/08/2022 1:35:37 PM
  • 25/07/2024 2:44:22 PM
  • 26/10/2023 5:16:00 PM
Company Name ADInstruments
Extension C L S I D {8EB6D491-A39D-43e2-841C-00FF298D2225}
Extension Type StandardExtension
File Description Video Render
File Version
  • 10.81.30400
  • 10.81.27400
  • 10.81.22400
Internal I D 1
Internal Name VideoRender
Internal Version 18.09
Legal Copyright
  • Copyright © 2008-2022 ADInstruments
  • Copyright © 2008-2023 ADInstruments
  • Copyright © 2008-2024 ADInstruments
Original Filename VideoRender(8).cfwext
Product Name
  • LabChart
  • LabChart Reader
Product Version
  • 8.1.30
  • 8.1.27
  • 8.1.22

File Traits

  • dll
  • x86

Block Information

Total Blocks: 1,532
Potentially Malicious Blocks: 11
Whitelisted Blocks: 588
Unknown Blocks: 933

Visual Map

? 0 ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 ? 0 ? ? ? 0 ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? 0 0 ? ? 0 ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? 0 ? ? 0 0 0 0 0 ? 0 ? 0 ? 0 0 ? 0 0 0 ? ? 0 0 0 ? ? ? ? ? 0 ? ? ? ? ? 0 ? 0 0 ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 0 ? 0 ? 0 ? ? ? 0 0 0 0 ? 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 ? ? 0 0 0 ? 0 ? 0 ? ? ? ? 0 ? 0 0 ? ? ? ? 0 0 ? ? 0 ? ? ? ? 0 ? ? 0 0 0 0 0 ? ? ? 0 0 0 ? ? ? ? 0 0 0 ? 0 ? ? 0 0 0 ? ? ? 0 ? 0 ? 0 ? 0 0 0 1 1 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? 1 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 ? 0 ? ? ? ? ? ? ? 0 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? 0 0 0 ? ? 0 ? ? 0 ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? 0 ? ? 0 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 ? 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 ? ? ? 0 0 ? ? 0 0 0 ? 0 ? 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 ? ? 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 0 ? ? 0 0 0 0 0 ? ? 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? x 0 0 ? ? ? ? 0 0 x 0 0 ? ? ? 0 ? ? ? 0 0 ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? 0 0 ? ? 0 ? ? 0 0 ? 0 0 ? ? ? ? 0 ? ? ? 0 0 ? ? ? ? 0 ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? ? 0 ? 0 0 0 x ? x 0 x 0 x 0 0 0 ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 ? ? ? 0 ? ? 0 x ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? 0 ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 ? 0 ? x ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 x ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x 0 ? 0 0 ? ? 0 ? 0 ? ? ? ? ? ? 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 0 0 ? 0 0 ? 0 ? ? ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 ? 0 ? ? ? 0 ? 0 ? 0 ? ? 0 0 0 0 ? 0 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 ? ? ? 0 0 0 0 ? ? ? 0 ? ? ? ? 0 0 0 ? 0 ? ? ? 0 ? ? 0 ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 0 ? ? ? 0 ? ? ? ? ? ? 0 0 ? ? ? ? ? 0 ? ? ? ? ? 0 0 ? ? ? 0 ? ? 0 ? 0 ? ? ? ? 0 0 0 ? 0 ? ? 0 ? 0 x ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 0 ? 0 ? ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 2 0 0 0 1 1 0 0 1 0 0 0 0 0 0 2 1 1 2 3 0 0 2 2 1 0 0 0 2 3 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 1 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\9699becbf35802b08fdcf0ada427fa8cdd24dc57_0000566784.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\ba7458a9b2e79ba19fad0cac4b72c66fcc40c58c_0000566784.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\3d65167b7183866e7389b30bbeaaddbd5392e9a5_0000566272.,LiQMAxHB

Trending

Most Viewed

Loading...