Threat Database Trojans Trojan.Agent.RTA

Trojan.Agent.RTA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 12,486
Threat Level: 80 % (High)
Infected Computers: 35
First Seen: November 5, 2024
Last Seen: July 7, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.RTA on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and its presence can lead to a range of problems, from data theft to system crashes. In this report, we will provide an overview of what Trojan.Agent.RTA is, how it operates, and the steps you can take to remove it from your system.

What Is Trojan.Agent.RTA?

Trojan.Agent.RTA is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate programs. The name Trojan.Agent.RTA suggests that it is a type of agent-based malware, but without more specific information, it is difficult to determine its exact characteristics or behaviors. Generally, Trojans are designed to allow unauthorized access to a computer system, and they can be used to steal sensitive information, install additional malware, or disrupt system operations.

How Trojan.Agent.RTA Operates

The exact operational details of Trojan.Agent.RTA are not available, but Trojans typically operate by exploiting vulnerabilities in software or tricking users into installing them. Once installed, they can communicate with their command and control servers to receive instructions, transmit stolen data, or download additional malware. Trojans can also use social engineering tactics to deceive users into performing certain actions that compromise system security. They may masquerade as useful programs or system files, making them difficult to detect without proper security tools.

Symptoms of Infection

Systems infected with Trojan.Agent.RTA or similar malware may exhibit a range of symptoms, including but not limited to, slow system performance, frequent crashes, unexpected pop-ups, or changes in browser settings. Users may also notice that their personal files are being accessed or modified without their consent, or that their internet connection is being used for suspicious activities. However, some Trojans are designed to operate stealthily, making it challenging for users to detect their presence without the aid of security software.

How to Remove Trojan.Agent.RTA

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for internet access to download removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove all instances of Trojan.Agent.RTA and other malware.
  3. Manually uninstall any suspicious programs that were installed around the time of the infection. Be cautious and only remove programs that you are certain are malicious or unnecessary.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings changes made by the malware.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all malware has been removed. Repeat this process until no more threats are detected.

Conclusion

The removal of Trojan.Agent.RTA from your system requires careful and systematic steps to ensure that all traces of the malware are eliminated. It is crucial to use reputable security tools and to follow best practices for system security to prevent future infections. Keeping your operating system, software, and security tools up to date, using strong antivirus protection, and being cautious when downloading or installing new programs can significantly reduce the risk of malware infections. Remember, vigilance and proactive security measures are key to maintaining the integrity and security of your computer system.

Analysis Report

General information

Family Name: Trojan.Agent.RTA
Signature status: No Signature

Known Samples

MD5: 138a926e789be2c2de3e21311d7765ef
SHA1: 36dbd9f70100b7987e216ee014e4a095d7d9e063
SHA256: 4BE27B1519EB96CB4FA9D5E4EBD84F0421D87A032844EAF441DCC36FE9167EA4
File Size: 145.41 KB, 145408 bytes
MD5: f521e5c6093727cb932e77586f09e95e
SHA1: c71a0d28f128fc54ca98146e3835ab63df260c44
SHA256: E1063BD7B402D5F8F80F6CF84BEA4BD1DE211AB7871AE12F56AF95B2C55E7425
File Size: 152.06 KB, 152064 bytes
MD5: 9730771f666a97d889e35026ea84d42c
SHA1: 011c34e68abb9fa7a39f8be838e345868e34dd65
SHA256: EF5224234CC453C6DCE9C1B8BF79B6273E8EAA0D6BB90F90D660E98AFBA6C2A4
File Size: 154.11 KB, 154112 bytes
MD5: 2c8ee42c6155ac324792dbbdada8f26c
SHA1: 3a5b44e265b5238403c0ba733a9bfd5098f0ac54
SHA256: DBF8FA1434A39B2C8D886E9A7924E2CBC8C4FCBB037EA3DCAA3E0432DF504EB6
File Size: 153.60 KB, 153600 bytes
MD5: 6cca583964120c47b62f462d4ee103ac
SHA1: 1d417f81f2fdc5b43711c0a6ae3a2c464896f8cd
SHA256: C1067626845E10FCC1E1BEF49FAF7ADDB46ECC2584A5C0C9AA16A4B124DF2402
File Size: 154.11 KB, 154112 bytes
Show More
MD5: 9b35114a6aff0c3a87cc9fcce5380229
SHA1: b018cf20943eca376ac59e28f6b95d3c3843d33e
SHA256: 5C5E42D7FBE116F73F61BA9B91C2A6CA3D25466AE9DA8DE5E83282A70AEED33A
File Size: 145.41 KB, 145408 bytes
MD5: f10275692ead7b57175931101e09fe2f
SHA1: c4d7d550465dd5b1b28b2b59a9047f42a354691f
SHA256: 77CE6F80EDB8836C1FD05307FD29C27DE28B0FB1592CE7F452B7426D73E096E1
File Size: 2.05 MB, 2046464 bytes
MD5: 6c9eafb4f0030e1b6e5ba8f2cc998f71
SHA1: c8a6b919cbc8f62378817d56ba57fb24ccfbc60f
SHA256: 0A9930268EE9F4BD81C5CE0B02549C0D230A227300582FEF74330F6B2E91427A
File Size: 139.26 KB, 139264 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • No Version Info
  • ntdll
  • x64

Block Information

Total Blocks: 348
Potentially Malicious Blocks: 60
Whitelisted Blocks: 268
Unknown Blocks: 20

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x 0 0 0 ? x x 0 x x x x x x ? ? x ? x x x x x x 0 x x x x 0 0 x x x ? x x x x 0 0 x 0 ? 0 0 0 0 0 0 0 0 x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x x x ? x x x x ? 0 0 0 x 0 0 0 0 1 0 0 0 0 0 0 0 1 0 x x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 x 0 ? ? ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 x 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\pshost.134205973625313723.8060.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
c:\users\user\appdata\local\temp\__psscriptpolicytest_ga44zreq.ajn.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_z5zr1cdc.0dn.psm1 Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe 䚛㢜쮟ǜ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelWaitCompletionPacket
Show More
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemEnvironmentValueEx
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects

7 additional items are not displayed above.

Network Winhttp
  • WinHttpConnect
  • WinHttpOpen
  • WinHttpOpenRequest
  • WinHttpQueryHeaders
  • WinHttpReceiveResponse
  • WinHttpSendRequest
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Other Suspicious
  • AdjustTokenPrivileges
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -NoProfile -NonInteractive -WindowStyle Hidden -Command "Set-MpPreference -DisableRealtimeMonitoring $true"

Trending

Most Viewed

Loading...