Threat Database Trojans Trojan.Go.Agent.A

Trojan.Go.Agent.A

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 15,934
Threat Level: 80 % (High)
Infected Computers: 5,110
First Seen: June 4, 2021
Last Seen: June 25, 2026
OS(es) Affected: Windows

The detection of Trojan.Go.Agent.A on your system indicates a potential security threat that requires immediate attention. Trojans are a type of malware that can cause significant harm to your computer and compromise your personal data. In this report, we will provide you with an overview of the threat, its operating methods, symptoms of infection, and steps to remove it from your system.

What Is Trojan.Go.Agent.A?

Trojan.Go.Agent.A is a type of Trojan horse malware that can infect your computer without your knowledge or consent. The name "Trojan" refers to the fact that this type of malware disguises itself as a legitimate program or file, allowing it to bypass security measures and gain access to your system. Once inside, it can cause a range of problems, from stealing your personal data to disrupting your computer's operation.

How Trojan.Go.Agent.A Operates

Trojan.Go.Agent.A, like other Trojans, operates by exploiting vulnerabilities in your system or deceiving you into installing it. It may arrive as an attachment or download from a suspicious email, a fake software update, or a compromised website. Once installed, it can communicate with its creators, allowing them to control your computer remotely, steal sensitive information, or use your system for malicious activities such as spamming or distributing malware.

Symptoms of Infection

Identifying a Trojan infection can be challenging because these malware types are designed to remain hidden. However, there are several symptoms that may indicate your system is infected with Trojan.Go.Agent.A or similar malware. These include unusual system behavior, such as unexpected crashes, slow performance, or unfamiliar programs appearing on your system. You might also notice changes in your browser settings, unexpected pop-ups, or your computer connecting to the internet without your input.

How to Remove Trojan.Go.Agent.A

  1. Boot into Safe Mode with Networking: This will help prevent the malware from loading and give you a cleaner environment to work in.
  2. Conduct a Full Scan: Use a reputable anti-malware tool, such as SpyHunter, to scan your system thoroughly. Ensure your anti-malware software is updated to the latest version for the best protection.
  3. Uninstall Suspicious Programs: Go through your installed programs and remove any that you don't recognize or that were installed around the time your system became infected.
  4. Reset Your Browser: Malware often affects web browsers, so resetting Chrome, Firefox, Edge, or any other browser you use can help remove malicious extensions or settings. Go to your browser's settings and look for the option to reset it to its default state.
  5. Reboot and Re-scan: After completing the above steps, restart your computer and run another full scan with your anti-malware tool to ensure that no remnants of the malware remain on your system.

Conclusion

Removing Trojan.Go.Agent.A from your system requires careful and thorough action. By following the steps outlined above and maintaining good security practices, such as regularly updating your software, using strong antivirus programs, and being cautious with emails and downloads, you can protect your system from future infections. Remember, prevention is key, but when an infection occurs, swift and informed action is crucial to minimizing damage and securing your personal data.

Analysis Report

General information

Family Name: Trojan.Go.Agent.A
Packers: UPX x64
Signature status: No Signature

Known Samples

MD5: 3d784121dff563dc20e3a3e160847617
SHA1: 58dd5341f2fb2824615bd31a8cb0ab8df468835d
SHA256: 9B7BD932C9D4F4B4476B5F213D523187518238F567A228F18FF4D33086F9C405
File Size: 3.10 MB, 3102720 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Windows Session Manager
File Version 10.0.20348.3089 (WinBuild.160101.0800)
Internal Name smss.exe
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename smss.exe
Product Name Microsoft® Windows® Operating System
Product Version 10.0.20348.3089

File Traits

  • 2+ executable sections
  • golang
  • HighEntropy
  • packed
  • upx
  • UPX x64
  • x64

Block Information

Total Blocks: 1,073
Potentially Malicious Blocks: 188
Whitelisted Blocks: 884
Unknown Blocks: 1

Visual Map

0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 x 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 x x x x x x 0 0 0 0 x 0 x x 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 x x x 0 x x x 0 0 x x 0 x x 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 x x x x 0 x x x 0 x x x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 x 0 x x 0 x 0 0 0 0 0 x 0 0 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 x x x 0 x 0 x 0 0 0 x 0 0 0 0 x x 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 x x 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x 0 x 0 x x 0 0 0 0 x 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x x x x x x x x 0 0 0 0 0 0 0 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Go.Agent.A
  • Go.Agent.D

Files Modified

File Attributes
c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\startup\nano3_10_1.lnk Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\notes.txt Generic Write,Read Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateTimer2
Show More
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtFlushBuffersFile
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletionEx
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetIoCompletion
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • ntdll.dll!NtYieldExecution
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Network Winsock2
  • WSAGetOverlappedResult
  • WSASend
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • bind
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • getpeername
  • getsockname
  • setsockopt
  • socket

Related Posts

Trending

Most Viewed

Loading...