Threat Database Trojans Trojan.Agent.KPSR

Trojan.Agent.KPSR

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 5
First Seen: November 19, 2025
Last Seen: March 19, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.KPSR on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operational methods, symptoms of infection, and most importantly, steps to remove it from your system. It's crucial to approach this situation with a calm and methodical mindset to ensure the complete eradication of the threat.

What Is Trojan.Agent.KPSR?

Trojan.Agent.KPSR is identified as a Trojan-type threat. Trojans are malicious programs that can allow unauthorized access to your system, steal your data, or disrupt your system's operation. The name "Trojan.Agent.KPSR" suggests it is a type of agent or component within a broader category of Trojan threats, designed to perform specific malicious functions on infected computers.

How Trojan.Agent.KPSR Operates

Understanding how Trojan.Agent.KPSR operates is key to removing it. Typically, Trojans are disguised as legitimate software or are embedded within legitimate programs. Once installed, they can create backdoors, allowing remote access to your system. They might also install additional malware, steal personal data, or disrupt system performance. The specific operations of Trojan.Agent.KPSR would depend on its design and the intentions of its creators, but like other Trojans, it likely aims to compromise system security and user privacy.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely but often include noticeable system slowdowns, frequent crashes, or unusual program behavior. You might also observe unauthorized changes to your system settings, unexpected pop-ups, or your browser being redirected to unwanted sites. In some cases, the infection might not display obvious symptoms, making it harder to detect without the use of security software.

How to Remove Trojan.Agent.KPSR

  1. Enter Safe Mode with Networking: This will limit the malware's ability to interfere with the removal process. Restart your computer and press the key to access your boot menu (usually F8, F12, or Del), then select Safe Mode with Networking.
  2. Perform a Full Scan: Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. Ensure your antivirus and anti-malware software are updated before scanning to increase the chances of detection and removal.
  3. Uninstall Suspicious Programs: Go through your installed programs and uninstall any that you don't recognize or that were installed around the time you suspect the infection occurred.
  4. Reset Your Browsers: Resetting browsers like Chrome, Firefox, or Edge can help remove any malicious extensions or settings that the Trojan might have altered. You can usually find this option in the browser's settings or preferences section.
  5. Reboot and Re-scan: After completing the above steps, reboot your system in normal mode and perform another full scan with your anti-malware tool to ensure that the threat has been completely removed.

Conclusion

Removing Trojan.Agent.KPSR requires a systematic approach to ensure your system's security and integrity. By understanding the nature of the threat and following the provided steps, you can effectively eliminate the malware. It's also crucial to adopt preventive measures, such as regularly updating your software, using strong, unique passwords, and being cautious with email attachments and downloads, to protect against future infections. Remember, staying informed and proactive is key to maintaining your digital security in an ever-evolving threat landscape.

Analysis Report

General information

Family Name: Trojan.Agent.KPSR
Signature status: No Signature

Known Samples

MD5: cdb3544e10f0109dd8830e17cf771620
SHA1: 1c34dc24fb9528ffac88b13b28273c2db34e68df
SHA256: 7BB5EAAE6187FC61A5F880CAC4C4FD98A29351A3220710240EC9281448C9DA0E
File Size: 88.06 KB, 88064 bytes
MD5: df71837d112be8ba89308ebe499a6f87
SHA1: 95cb786b9657b4a376142998ddff819274bea2d7
SHA256: 1FCA1C1D91A67F9BF4702FC90104F855F7B3A258E19C1E96C993F638875BD805
File Size: 87.04 KB, 87040 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • GetConsoleWindow
  • No Version Info
  • x64

Block Information

Total Blocks: 148
Potentially Malicious Blocks: 31
Whitelisted Blocks: 114
Unknown Blocks: 3

Visual Map

0 0 0 0 0 0 0 0 0 0 ? x x ? ? 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 0 x x x x 0 0 x 0 0 0 0 x x x x x 0 0 0 0 x 0 x x 0 0 x x 0 x 0 x 0 x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.KPSR
  • Trojan.Agent.Gen.IM
  • Trojan.Agent.Gen.IW
  • Trojan.Agent.Gen.LV

Files Modified

File Attributes
\device\namedpipe\discord-ipc-0 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\discord-ipc-1 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\discord-ipc-2 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\discord-ipc-3 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\discord-ipc-4 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\discord-ipc-5 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\discord-ipc-6 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\discord-ipc-7 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\discord-ipc-8 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\discord-ipc-9 Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
\device\namedpipe\srvsvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\microsoft\systemcache\runtimebroker.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\roaming\microsoft\systemcache\runtimebroker.exe Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-��LG=�A��J� �C� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\runonce::systemcacheupdate cmd /c start /min "" "C:\Users\Okszazwa\AppData\Roaming\Microsoft\SystemCache\RuntimeBroker.exe" RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 �  xy* �/��Y�d�kP~� ��ރ�p��^�o���zeeKVs}kP~��1f��7 ���ﺃee��� ��1��fe��g RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k8��81z��B�8 �6 �v y� z �Z xy �� �a ۀ��T�B������1�����5����ee +Bx�<����5�R � �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[ RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\runonce::systemcacheupdate cmd /c start /min "" "C:\Users\Okszazwa\AppData\Roaming\Microsoft\SystemCache\RuntimeBroker.exe" RegNtPreCreateKey
HKCU\discord-1334595983404699718:: URL:Run game 1334595983404699718 protocol RegNtPreCreateKey
HKCU\discord-1334595983404699718::url protocol RegNtPreCreateKey
HKCU\discord-1334595983404699718\defaulticon:: C:\Users\Okszazwa\AppData\Roaming\Microsoft\SystemCache\RuntimeBroker.exe RegNtPreCreateKey
HKCU\discord-1334595983404699718\shell\open\command:: C:\Users\Okszazwa\AppData\Roaming\Microsoft\SystemCache\RuntimeBroker.exe RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ߌ듢ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 -k8��8tX��B�8 �� �6 �v 5� �Z xy ��T���B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�0 RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\runonce::systemcacheupdate C:\Users\Godtekpk\AppData\Roaming\Microsoft\SystemCache\RuntimeBroker.exe RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 .k8��8tX��B�8 �� �6 �v 5� �Z xy ��T���B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�0 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ~� % xy* �/��Y�d�kP~� ��ރ�p��^�o���zee+Vs} kP~ ��1���7 ���ﺃee����1��fe��h�n RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 /k8��8tX��B�8 �� �6 �v 5� �Z xy ����T���B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 0k8��8tX��B�8 �� �6 �v 5� �Z xy ����T���B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D RegNtPreCreateKey
HKCU\discord-1334595983404699718\defaulticon:: C:\Users\Godtekpk\AppData\Roaming\Microsoft\SystemCache\RuntimeBroker.exe RegNtPreCreateKey
HKCU\discord-1334595983404699718\shell\open\command:: C:\Users\Godtekpk\AppData\Roaming\Microsoft\SystemCache\RuntimeBroker.exe RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAccessCheckByType
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcCreatePortSection
  • ntdll.dll!NtAlpcCreateSectionView
Show More
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcQueryInformationMessage
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAreMappedFilesTheSame
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelIoFileEx
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateUserProcess
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtImpersonateAnonymousToken
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryEvent
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory

18 additional items are not displayed above.

Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • ShellExecute
  • ShellExecuteEx
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Shell Command Execution

(NULL) C:\Users\Okszazwa\AppData\Roaming\Microsoft\SystemCache\RuntimeBroker.exe
open C:\Users\Godtekpk\AppData\Roaming\Microsoft\SystemCache\RuntimeBroker.exe

Trending

Most Viewed

Loading...