Trojan.Agent.JCK
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Popularity Rank: | 15,044 |
| Threat Level: | 80 % (High) |
| Infected Computers: | 32 |
| First Seen: | May 12, 2025 |
| Last Seen: | July 10, 2026 |
| OS(es) Affected: | Windows |
The detection of Trojan.Agent.JCK on your system indicates a potential security threat that requires immediate attention. This type of threat is categorized as a Trojan, which is a broad term for malicious software that disguises itself as legitimate to gain unauthorized access to a computer system. The presence of Trojan.Agent.JCK suggests that your system may have been compromised, and it is essential to understand the nature of this threat and take appropriate steps to remove it.
Table of Contents
What Is Trojan.Agent.JCK?
Trojan.Agent.JCK is a type of malware that can infect a computer system without the user's knowledge or consent. The term "Trojan" refers to the method of infection, where the malware disguises itself as a legitimate program or file to gain access to the system. Once inside, the malware can perform various malicious activities, such as stealing sensitive information, installing additional malware, or providing unauthorized access to the system.
How Trojan.Agent.JCK Operates
The exact operation of Trojan.Agent.JCK may vary, but common characteristics of Trojan-type malware include the ability to hide from the system and security software, communicate with command and control servers, and download or install additional malware. Trojans can also create backdoors, allowing unauthorized access to the system, and can be used to steal sensitive information, such as login credentials, credit card numbers, or personal data.
Symptoms of Infection
Systems infected with Trojan.Agent.JCK may exhibit various symptoms, including slow system performance, unexpected crashes, or unusual network activity. Users may also notice unfamiliar programs or icons on their system, or receive unexpected pop-ups or alerts. In some cases, the malware may not exhibit any noticeable symptoms, making it difficult to detect without the use of security software.
How to Remove Trojan.Agent.JCK
- Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
- Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove the malware.
- Uninstall any suspicious programs or applications that may be related to the malware.
- Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
- Reboot your system and perform another full scan to ensure that the malware has been completely removed.
Conclusion
The detection of Trojan.Agent.JCK is a serious security issue that requires prompt attention. By understanding the nature of this threat and following the steps outlined above, you can help to remove the malware and prevent further damage to your system. It is essential to remain vigilant and take proactive measures to protect your system from future threats, including keeping your operating system and security software up to date, using strong passwords, and avoiding suspicious downloads or links.
Analysis Report
General information
| Family Name: | Trojan.Agent.JCK |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
9e4b5030d317d7aa05e1df4f0cf32f5d
SHA1:
38d437726d6359e6ca436bbb423e6aafcb347cf8
SHA256:
E8391AED68FFA3050845A202DAAF91AF7B6DA802192E483AB7E698B5D9869EED
File Size:
4.87 MB, 4872323 bytes
|
|
MD5:
3d0363db7d308459704855ee3b9bb3af
SHA1:
c26ed845d5647bf02718de0b55543712c0ea8d68
SHA256:
A5DE533408DDDFB81269C54B3451F6705859CAC4197BB3862BDC0A0C83141C48
File Size:
5.12 MB, 5119502 bytes
|
|
MD5:
f54c8efef50d87d702461a14dfb64427
SHA1:
add4b92948a21c3bcf2408826b722d95ed7f813c
SHA256:
F3D7328C2DBCC0BF7AC9133D08E8D0F78330C3F13CECBC9107EDEC543A7B2816
File Size:
4.14 MB, 4135940 bytes
|
|
MD5:
8a1653f4211ad5521d78704d70cb1fe5
SHA1:
4348168c37b7e10c5193add9fb852de07ea64aa6
SHA256:
A30FAAAB7C06F03533D93C8F39B3107020BA7F5DDE6146F4218159546836935A
File Size:
2.20 MB, 2204371 bytes
|
|
MD5:
c38a298935693435d0bb5715452fed88
SHA1:
97a689e3debc22a5b378dcd1f31b538ed2ed0419
SHA256:
A91E18F0D1940AFB95FBCDE6D3438B366167396586DBDCEF286E6BED1CBCDB83
File Size:
2.78 MB, 2779921 bytes
|
Show More
|
MD5:
00003baf602cee7c591ff5ecc8eed045
SHA1:
2d250f03049076699e71b2139b8a3d4df6881a81
SHA256:
BFBCE8C629993801F6A10239DA0EC85DB77383411B2B07FA994E98B0DDBBC2F2
File Size:
7.31 MB, 7309252 bytes
|
|
MD5:
7bee5281eaf454f4f6d62ece6c5afdd4
SHA1:
dc622d0b5b55642de7619c4403403a7e19c20346
SHA256:
B242A33193D6493A7F2F373938F264569515D686D44BD50E6DF1087F2980E022
File Size:
3.29 MB, 3294787 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have resources
- File doesn't have security information
- File has TLS information
- File is 32-bit executable
- File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
- File is either console or GUI application
Show More
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.File Traits
- big overlay
- HighEntropy
- imgui
- No Version Info
- WriteProcessMemory
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 7,706 |
|---|---|
| Potentially Malicious Blocks: | 108 |
| Whitelisted Blocks: | 7,508 |
| Unknown Blocks: | 90 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Agent.JCK
- Agent.JIB
- Agent.OFSF
- Agent.OFSL
- ClipBanker.LH
Show More
- Kryptik.HLB
- Kryptik.HLF
- Kryptik.KFSB
- Malex.CC
- Malex.N
- PSW.Discord.K
- REntS.D
- XRatLocker.B
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| c:\users\user\appdata\local\temp\2145531.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\roaming\openboardview\obv.conf | Generic Write,Read Attributes |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKCU\software\microsoft\windows\currentversion\run::add4b92948a21c3bcf2408826b722d95ed7f813c_0004135940 | c:\users\user\downloads\add4b92948a21c3bcf2408826b722d95ed7f813c_0004135940 | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Anti Debug |
|
| Keyboard Access |
|