Threat Database Trojans Trojan.Agent.JJ

Trojan.Agent.JJ

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 18,604
Threat Level: 80 % (High)
Infected Computers: 195
First Seen: September 11, 2022
Last Seen: June 6, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.JJ on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to take steps to remove it as soon as possible. In this report, we will provide you with information on what Trojan.Agent.JJ is, how it operates, the symptoms of infection, and most importantly, how to remove it from your system.

What Is Trojan.Agent.JJ?

Trojan.Agent.JJ is a type of Trojan horse malware that can infect your computer and allow unauthorized access to your system. Trojans are a type of malware that disguise themselves as legitimate programs, but in reality, they are designed to cause harm to your computer. The name Trojan.Agent.JJ suggests that it is a type of agent-based Trojan, which means it can perform various malicious actions on your system.

How Trojan.Agent.JJ Operates

Trojans like Trojan.Agent.JJ typically operate by exploiting vulnerabilities in your system or by tricking you into installing them. Once installed, they can create backdoors, allowing hackers to access your system remotely. They can also steal sensitive information, such as passwords, credit card numbers, and personal data. Additionally, Trojans can install other types of malware, such as spyware, adware, or ransomware, which can further compromise your system's security.

Symptoms of Infection

The symptoms of a Trojan.Agent.JJ infection can vary, but common signs include slow system performance, unexpected pop-ups, and suspicious network activity. You may also notice that your system is crashing frequently or that your browser is being redirected to unwanted websites. In some cases, you may not notice any symptoms at all, which is why it's essential to run regular virus scans to detect and remove malware like Trojan.Agent.JJ.

How to Remove Trojan.Agent.JJ

  1. Restart your computer in Safe Mode with Networking to prevent the malware from loading.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and remove any detected threats.
  3. Uninstall any suspicious programs or applications that you don't recognize or that were installed recently.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and run another scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Agent.JJ from your system requires careful attention to detail and a thorough understanding of the malware removal process. By following the steps outlined in this report, you can help ensure that your system is free from this type of malware. Remember to always be cautious when installing new software, and never click on suspicious links or download attachments from unknown sources. Regular virus scans and updates to your operating system and security software can also help prevent future infections. If you're unsure about any aspect of the removal process, consider seeking help from a professional IT technician or a reputable security expert.

Analysis Report

General information

Family Name: Trojan.Agent.JJ
Signature status: No Signature

Known Samples

MD5: b929cc4a484aaffbfba64efe29b3c863
SHA1: 1c9d28a84e75b06e284b1ca297db726095b6e2be
File Size: 9.22 KB, 9216 bytes
MD5: e6f1d7936234cbc2dd631883c09bfa79
SHA1: 97def376c6f80ec11ad782c3f5998ddc418fc780
File Size: 9.22 KB, 9216 bytes
MD5: dc10823bf2cd254a4457aa5fa5ff61ad
SHA1: 9bac4b608c8f35b32dd68f932a68dc51db14bc11
SHA256: D12ECCB3BC7517E0F5896CAFB49323D41085373330A4B584A3BEDAA0071AC1C0
File Size: 9.22 KB, 9216 bytes
MD5: d0273276cf9cd69677848d4f0dcbc917
SHA1: 8432ab3edc1a71c257fc147c283c943195ab9ed3
SHA256: 4838E60A2DFD7C4215BB65AEA6B44870E07893E3ABD773E038C52E3B1F95D8DC
File Size: 9.22 KB, 9216 bytes
MD5: 481dda8f59e1ad9bc7b866e9e42b51ba
SHA1: dfdb7709a91c20d882d818b3eba5f169d8b64f64
SHA256: 62BFF4B98379BCAD1766A864128D219670F63BDA760ECC427D4125B159516A75
File Size: 9.22 KB, 9216 bytes
Show More
MD5: 14c29b54e6479826193187ff11bb5b71
SHA1: 6880a81abd8e79ef84c720b695143ffcc11f253d
SHA256: 7E7F54081868B2941C434830EE74B98E215F72CDAA6A9B5E3811B80191A63FB4
File Size: 9.22 KB, 9216 bytes
MD5: 2831fa5bb41b1780124f39960f326bf3
SHA1: 768e213358743ca9490dd76616f17b63bdf2e40d
SHA256: 93A566AE863FFD6ED525C673233B9D61ACFB84060381AB40087634E1CE3338F3
File Size: 9.22 KB, 9216 bytes
MD5: 2615fb3220fa4657542d81b222ea2c13
SHA1: 4d7bc7d48d2f1a8cd9adfbb27eb31ea2ef9a4f13
SHA256: 603AFA9B0DB5A2222D194CB16A25A2F7E4E8B2C7A1A050320DE6289A5D5660C6
File Size: 9.22 KB, 9216 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Version 1.0.0.0
Internal Name
  • alit.exe
  • batson.exe
  • creepers.exe
  • distancing.exe
  • grandchild.exe
  • marketability.exe
  • subtitles.exe
  • torii.exe
Original Filename
  • alit.exe
  • batson.exe
  • creepers.exe
  • distancing.exe
  • grandchild.exe
  • marketability.exe
  • subtitles.exe
  • torii.exe
Product Version 1.0.0.0

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 2
Potentially Malicious Blocks: 2
Whitelisted Blocks: 0
Unknown Blocks: 0

Visual Map

x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.JJ

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 +k�8��8tX��B �� �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�-&�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data 隞̃ﰁ耀꧌ŧड़ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k8��81��B�8 �6 �v y� �Z xy �� �a ۀT�B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�-&�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9�/�� RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data 隞̃耀꧌Шx RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
Show More
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile

1 additional items are not displayed above.

User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Other Suspicious
  • AdjustTokenPrivileges
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider

Shell Command Execution

C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 704
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 508
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 712

Related Posts

Trending

Most Viewed

Loading...