Threat Database Trojans Trojan.Amadey.B

Trojan.Amadey.B

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 18,811
Threat Level: 80 % (High)
Infected Computers: 287
First Seen: March 7, 2023
Last Seen: April 24, 2026
OS(es) Affected: Windows

The detection of Trojan.Amadey.B on your system indicates a potential security threat that requires immediate attention. This report provides an overview of the threat, its operating methods, symptoms of infection, and a step-by-step guide on how to remove it from your system.

What Is Trojan.Amadey.B?

Trojan.Amadey.B is a type of malicious software that can compromise the security and integrity of your computer system. The term "Trojan" refers to a broad category of malware that disguises itself as legitimate software, allowing it to bypass security defenses and gain unauthorized access to a system. While the specific characteristics of Trojan.Amadey.B may vary, its primary goal is to cause harm or exploit system vulnerabilities for malicious purposes.

How Trojan.Amadey.B Operates

Malware like Trojan.Amadey.B typically operates by exploiting system vulnerabilities or tricking users into installing it. Once installed, it can perform a variety of malicious actions, including data theft, unauthorized access to system resources, and the installation of additional malware. The exact methods used by Trojan.Amadey.B can depend on its specific design and the intentions of its creators, but the end result is often a compromised system that is vulnerable to further exploitation.

Symptoms of Infection

Symptoms of a Trojan.Amadey.B infection can vary widely, depending on the specific actions it is designed to perform. Common indicators of a malware infection include slow system performance, unexpected pop-ups or advertisements, unfamiliar programs or icons, and changes to system settings or browser behavior. If you suspect that your system is infected with Trojan.Amadey.B or any other type of malware, it is essential to take immediate action to remove the threat and prevent further damage.

  • Unexplained changes to system settings or browser behavior
  • Appearance of unfamiliar programs or icons
  • Slow system performance or frequent crashes
  • Unexpected pop-ups or advertisements

How to Remove Trojan.Amadey.B

  1. Boot your system into Safe Mode with Networking to prevent the malware from loading and to allow for internet access. This will make it easier to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove all traces of the malware.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time the malware was detected.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings that may have been installed by the malware.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.Amadey.B from your system requires careful attention to detail and a systematic approach to ensure that all components of the malware are eliminated. By following the steps outlined in this report and maintaining good security practices, such as regularly updating your operating system and software, using strong antivirus protection, and being cautious when installing new programs or clicking on links, you can help protect your system against future malware infections and keep your data safe.

Analysis Report

General information

Family Name: Trojan.Amadey.B
Signature status: No Signature

Known Samples

MD5: a5e6484eef2b273591ad13582eb657de
SHA1: d9c52dfb831c575dca98eef953da8816da73db8e
File Size: 425.98 KB, 425984 bytes
MD5: 9ac5cbd32dfbe6cf6260005d2ff74e58
SHA1: 4f8d96a6c3902ac93e995587728b84fab9efef62
File Size: 425.98 KB, 425984 bytes
MD5: 19cd3c6d17d45c9de97240011b9e6b1d
SHA1: 85c1e5add3ff1e4499136dc9f1643bbf88f16825
SHA256: FB14B67779559AF123E61B6D205E27CD79952C5356D6077C0546575538BAA5BE
File Size: 421.38 KB, 421376 bytes
MD5: 0a4b8bea6ac02a4455eab48260650a04
SHA1: b587dacd5151f890df962e04c4aa210472246c46
SHA256: 29DAB397E67EEACE29B0DA16C861B2D3763F09B7B8BC143BDA572070B28D6BF2
File Size: 398.34 KB, 398336 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Win32 Cabinet Self-Extractor
File Version 11.00.17763.1 (WinBuild.160101.0800)
Internal Name Wextract
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename WEXTRACT.EXE .MUI
Product Name Internet Explorer
Product Version 11.00.17763.1

File Traits

  • No Version Info
  • WriteProcessMemory
  • x86

Block Information

Similar Families

  • Androm.YA
  • Androm.YBBB
  • Dropper.Agent.SDA

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\bd4cae89c3\suker.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\ixp000.tmp\t8749161.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\t8749161.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\tmp4351$.tmp Generic Write,Read Attributes,Delete
c:\users\user\appdata\local\temp\ixp000.tmp\z3796815.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\z3796815.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\p7305499.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\p7305499.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\r4086870.exe Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\ixp001.tmp\r4086870.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\tmp4351$.tmp Generic Write,Read Attributes,Delete

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 Y� xykP~�ރ������^۴���z}�OVs}kP~�)���1K�����dB F e���1��}e��e�� RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup0 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qpzzwtls\AppData\Local\Temp\IXP000.TMP\" RegNtPreCreateKey
Show More
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup1 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Qpzzwtls\AppData\Local\Temp\IXP001.TMP\" RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
  • ShellExecute
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDuplicateObject
Show More
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Service Control
  • OpenSCManager
  • OpenService
  • StartService
Other Suspicious
  • AdjustTokenPrivileges
Anti Debug
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider

Shell Command Execution

C:\Users\Tmzmdyhm\AppData\Local\Temp\bd4cae89c3\suker.exe
C:\Users\Qpzzwtls\AppData\Local\Temp\IXP000.TMP\z3796815.exe
C:\Users\Qpzzwtls\AppData\Local\Temp\IXP001.TMP\p7305499.exe
C:\Users\Qpzzwtls\AppData\Local\Temp\IXP001.TMP\r4086870.exe

Trending

Most Viewed

Loading...