Threat Database Trojans Trojan.Agent.XXD

Trojan.Agent.XXD

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 14,992
Threat Level: 80 % (High)
Infected Computers: 22
First Seen: February 26, 2025
Last Seen: June 26, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.XXD on your system indicates a potential security threat that requires immediate attention. Trojans are a type of malware that can cause significant harm to your computer and compromise your personal data. In this removal report, we will provide you with general guidance on how to deal with this threat and prevent future infections.

What Is Trojan.Agent.XXD?

Trojan.Agent.XXD is a type of Trojan horse malware that can infect your computer without your knowledge or consent. The name "Trojan.Agent.XXD" suggests that it is a generic detection for a Trojan-type threat, but the actual nature and behavior of the malware can vary. Trojans are often disguised as legitimate software or attachments, making them difficult to detect. They can be used to steal sensitive information, install additional malware, or provide unauthorized access to your system.

How Trojan.Agent.XXD Operates

Once installed, Trojan.Agent.XXD can operate in various ways, depending on its intended purpose. It may attempt to connect to a command and control server to receive instructions or transmit stolen data. The malware can also install additional components or update itself to evade detection. In some cases, Trojans can create backdoors, allowing hackers to access your system remotely. The exact operation of Trojan.Agent.XXD is unknown, but it is essential to remove it as soon as possible to prevent further damage.

Symptoms of Infection

The symptoms of a Trojan infection can be subtle, making it challenging to detect the malware. You may notice slow system performance, unexpected crashes, or unfamiliar programs running in the background. Some Trojans can also cause changes to your system settings, such as altered homepage settings or new toolbars in your web browser. If you suspect that your system is infected with Trojan.Agent.XXD, it is crucial to take immediate action to remove the threat.

How to Remove Trojan.Agent.XXD

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the malware.
  3. Uninstall any suspicious programs or applications that may be related to the Trojan infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings.
  5. Reboot your system and perform another full scan to ensure that the malware has been completely removed.

It is essential to note that removing Trojan.Agent.XXD requires caution and patience. You may need to repeat the removal process several times to ensure that all instances of the malware have been eliminated.

Conclusion

The detection of Trojan.Agent.XXD on your system is a serious issue that requires immediate attention. By following the removal steps outlined above and taking preventive measures, such as keeping your operating system and software up to date, using strong antivirus software, and avoiding suspicious downloads, you can help protect your system from future infections. Remember to always be cautious when downloading software or opening attachments from unknown sources, and never provide personal or financial information to untrusted websites or applications.

Analysis Report

General information

Family Name: Trojan.Agent.XXD
Signature status: No Signature

Known Samples

MD5: 757b0b7de5a95e5d2a55599a45c8cc8b
SHA1: a3dbf54ad852018d63cb9cbc486905db2af03d61
SHA256: 9DB252C1B966DB2F2411D0AD6F381DCA3592506F81CF9DDDFFB7F95EAA671FAF
File Size: 399.87 KB, 399872 bytes
MD5: fd4785443aa4bc4341f74415a419e767
SHA1: d4b353ff70472b107769ed667c93698eb57d5b4f
SHA256: 3D1BAD29F47A748E6E424E01534D5C2B1543A21F0AA83643FB34EA3116823ED4
File Size: 437.76 KB, 437760 bytes
MD5: f032d47ac3536dc14e0166ff08f5653b
SHA1: 0c307c079e47d55b0b1c6547b9df44221b16b025
SHA256: C5EAD8C9883409B112AB21832A51C6A20E83E87AE70EF33F7E20FA6D08D5CF43
File Size: 275.97 KB, 275968 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name
  • Bodycam
  • Tsuda Kageyu
File Description
  • Bodycam Library
  • MinHook - The Minimalistic API Hook Library for x64/x86
File Version
  • 1.3.3.0
  • 0.1.2.8
Internal Name
  • Bodycam
  • MinHookD
Legal Copyright
  • Copyright (C) 2009-2017 Tsuda Kageyu. All rights reserved.
  • Copyright (C) 2024-2024 Bodycam. All rights reserved.
Legal Trademarks
  • Bodycam
  • Tsuda Kageyu
Product Name
  • Bodycam DLL
  • MinHook DLL
Product Version
  • 1.3.3.0
  • 0.1.2.8

File Traits

  • dll
  • HighEntropy
  • imgui
  • x64

Block Information

Total Blocks: 618
Potentially Malicious Blocks: 96
Whitelisted Blocks: 296
Unknown Blocks: 226

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 ? 0 0 0 0 0 0 0 0 x x x x 0 ? ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 x x x ? ? ? ? 1 ? 0 0 0 0 ? ? ? 0 ? ? 0 0 ? ? 0 ? 0 ? 0 ? 0 0 x x x x x ? ? ? ? ? ? 0 ? 0 ? 0 0 0 ? 0 ? ? ? 0 ? ? ? ? ? ? 0 0 0 ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 x x x x x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 ? ? 1 0 ? 0 0 ? ? ? 0 ? ? ? ? 0 0 0 0 0 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 ? ? ? ? x ? ? ? ? x x x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x x ? ? ? ? ? ? x x ? ? ? x x x ? x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? x x ? ? ? x x x x ? ? x x ? ? ? ? x x ? ? ? x x x x x x ? ? ? x x x x x x x x ? x x x x ? x x x x ? ? ? ? ? ? ? ? ? ? ? x x ? ? x x ? ? x x x x x x x x ? ? ? x x ? ? ? x x x x x x x x x x ? x x x x ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? 0 0 ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe �1k���� RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
Show More
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Anti Debug
  • IsDebuggerPresent
Process Terminate
  • TerminateProcess

Trending

Most Viewed

Loading...