Threat Database Trojans Trojan.Agent.HFK

Trojan.Agent.HFK

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 2
First Seen: November 15, 2025
Last Seen: April 4, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.HFK indicates that your system has been compromised by a potentially malicious program. This type of threat is generally categorized as a Trojan, which is a broad term for malware that disguises itself as legitimate software. The primary concern with Trojans is their ability to allow unauthorized access to your computer, potentially leading to the theft of personal data, disruption of system operation, or further malware installation.

What Is Trojan.Agent.HFK?

Trojan.Agent.HFK, as detected, suggests it is a variant of Trojan-type malware. The specifics of its operation and goals can vary, but its core function is to infiltrate a system without being detected and then perform malicious activities. The name itself does not directly indicate a specific malware family but rather categorizes it based on its behavior and characteristics.

How Trojan.Agent.HFK Operates

Trojan.Agent.HFK, like other Trojans, operates by deceiving users into installing it on their systems. This can happen through various means, such as downloading software from untrusted sources, opening malicious email attachments, or visiting compromised websites. Once installed, it can create backdoors, allowing remote access to the system, steal sensitive information, or install additional malware.

Symptoms of Infection

Symptoms of a Trojan infection can be subtle and may not always be immediately noticeable. However, common indicators include unusual system behavior, such as unexpected pop-ups, slow system performance, or programs launching without user initiation. Sometimes, the presence of a Trojan might only be discovered during a system scan with security software or when the malware's activities trigger security alerts.

  • Unexplained changes in system settings or files.
  • Increased network activity without a clear cause.
  • Appearance of unfamiliar programs or icons.

How to Remove Trojan.Agent.HFK

  1. Boot your computer in Safe Mode with Networking to limit the malware's ability to interfere with the removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and remove any detected threats.
  3. Manually uninstall any recently installed or suspicious programs from your system's control panel.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure all threats have been removed.

Conclusion

Removing Trojan.Agent.HFK requires careful steps to ensure the malware is completely eradicated from your system. It's crucial to act promptly to prevent further damage or data theft. After removal, consider taking preventive measures such as keeping your operating system and software up to date, being cautious with email attachments and downloads, and regularly scanning your system for malware to protect against future infections.

Analysis Report

General information

Family Name: Trojan.Agent.HFK
Signature status: No Signature

Known Samples

MD5: d804b844691c5d23f1d4cd00049f3ad5
SHA1: 93cd1a3f1b7b925e472fe596f9ef446a5f456e0b
SHA256: 3DF4BCFD7E83942C18EA2A4BC44936A2FF0111BCAA69849CE08777E7E76E50C0
File Size: 48.13 KB, 48133 bytes
MD5: c477b15f5b9126f9432cb4f574bbb3b0
SHA1: 85ba931aeaac0bc7b21e37c1fa3fc06d6062110a
SHA256: A68DEBCBB89456EB41ABBA6C9732CC67DEDA5E975B2A0CC0C23D9CD4594E6B07
File Size: 48.14 KB, 48143 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • No Version Info
  • x64

Block Information

Total Blocks: 121
Potentially Malicious Blocks: 108
Whitelisted Blocks: 13
Unknown Blocks: 0

Visual Map

x x x x x 1 x 1 x 1 x x x x x x x 1 x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 1 x x x x 0 x x x x 0 x x 0 x x x x 1 x x x 0 0 x x x x x x x x 0 x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.HFK

Files Modified

File Attributes
\device\namedpipe\local\mojo.6360.8812.7817453059033335160 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\local\mojo.7572.4244.16398808438417159389 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
c:\users\user\downloads\35syx04x3sity4.exe Generic Write,Read Attributes
c:\users\user\downloads\3r8x1gr0pkdyhvlo.xh5hh Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\3r8x1gr0pkdyhvlo.xh5hh Synchronize,Write Data
c:\users\user\downloads\6v8qabq6pbuxc.6ux Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\6v8qabq6pbuxc.6ux Synchronize,Write Data
c:\users\user\downloads\85ba931aeaac0bc7b21e37c1fa3fc06d6062110a_0000048143 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\93cd1a3f1b7b925e472fe596f9ef446a5f456e0b_0000048133 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\asqfq7flxteg.exe Generic Write,Read Attributes
Show More
c:\users\user\downloads\au7r1xzsmw8l0i.jvtk Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\au7r1xzsmw8l0i.jvtk Synchronize,Write Data
c:\users\user\downloads\bdhjiv2blc4aiqp.ugfg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\bdhjiv2blc4aiqp.ugfg Synchronize,Write Data
c:\users\user\downloads\fmv1gzpgix.jc3wnl Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\fmv1gzpgix.jc3wnl Synchronize,Write Data
c:\users\user\downloads\hkjcvchiykpf3.ldm2i Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\hkjcvchiykpf3.ldm2i Synchronize,Write Data
c:\users\user\downloads\hzrdu09ym.og3 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\hzrdu09ym.og3 Synchronize,Write Data
c:\users\user\downloads\lrt4pu9li9.jyl Synchronize,Write Data
c:\users\user\downloads\unn4mdvm8grz.xq4t Synchronize,Write Data
c:\users\user\downloads\vgux4fxgc2flf.vze Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\vgux4fxgc2flf.vze Synchronize,Write Data

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAccessCheckByType
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcCreatePortSection
  • ntdll.dll!NtAlpcCreateResourceReserve
Show More
  • ntdll.dll!NtAlpcCreateSectionView
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcQueryInformationMessage
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateNamedPipeFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateUserProcess
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFindAtom
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtImpersonateAnonymousToken
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryEvent
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueueApcThread
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletion
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread

30 additional items are not displayed above.

Process Manipulation Evasion
  • NtUnmapViewOfSection

Trending

Most Viewed

Loading...