Threat Database Trojans Trojan.Go.Agent.F

Trojan.Go.Agent.F

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 9,029
Threat Level: 80 % (High)
Infected Computers: 71
First Seen: February 6, 2023
Last Seen: June 23, 2026
OS(es) Affected: Windows

The detection of Trojan.Go.Agent.F on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to understand its nature and take steps to remove it.

What Is Trojan.Go.Agent.F?

Trojan.Go.Agent.F is a type of Trojan horse malware that can infect your computer through various means, such as downloading malicious software, opening infected email attachments, or visiting compromised websites. The name "Trojan" refers to the fact that this malware disguises itself as a legitimate program or file, allowing it to bypass security defenses and gain access to your system.

How Trojan.Go.Agent.F Operates

Once inside your system, Trojan.Go.Agent.F can operate in various ways, depending on its intended purpose. It may attempt to steal sensitive information, such as login credentials, credit card numbers, or personal data. It can also install additional malware, create backdoors for remote access, or disrupt system performance. The malware may communicate with its command and control servers to receive updates or transmit stolen data.

Trojan.Go.Agent.F can be particularly challenging to detect, as it may not exhibit obvious symptoms of infection. However, it's crucial to be aware of the potential risks and take proactive steps to protect your system and data.

Symptoms of Infection

While Trojan.Go.Agent.F may not always display noticeable symptoms, some common signs of infection include slow system performance, unexpected pop-ups or ads, and unfamiliar programs or icons on your desktop. You may also experience frequent crashes, freezes, or error messages. Additionally, you might notice that your browser homepage or search engine has been changed without your consent.

  • Unexplained changes to system settings or configuration
  • Increased network activity or unusual data transmissions
  • Appearance of suspicious files or folders
  • Difficulty installing or updating security software

How to Remove Trojan.Go.Agent.F

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove the malware.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Go.Agent.F from your system requires careful attention to detail and a thorough approach. By following the steps outlined above and maintaining good security practices, such as keeping your operating system and software up to date, using strong passwords, and avoiding suspicious downloads, you can help protect your computer and data from future malware infections. Remember to always be cautious when browsing the internet and to use reputable security tools to stay safe online.

Analysis Report

General information

Family Name: Trojan.Go.Agent.F
Signature status: Hash Mismatch

Known Samples

MD5: 5eda99ce780d95e2abc95d4aca34376e
SHA1: 49c31f17c89df90cd2ce0c9b7a2a0d04165f99c8
File Size: 1.73 MB, 1732696 bytes
MD5: 273edc08cd1a0ad55c114fe279b9306f
SHA1: 5ac9ff804517c2cfcc267a9a8c4a689ca5a44b9c
SHA256: 25B089AFE7C63A09D42643511DC400D96F6F39318A609DC7FDFF82539A34F975
File Size: 1.78 MB, 1778544 bytes
MD5: 92b7f7532e35c565869d6c7aabf3a854
SHA1: 1bc658aed19e1d342baaa9e04277950d2d707798
SHA256: 469F90462E164ACA083750A916BB223CA0B7F6285185C987C6234DE0D457BFC8
File Size: 1.37 MB, 1367984 bytes
MD5: 6888f859d1ed3dcd66ebdce5dc361f2e
SHA1: 7cc15ef4caa62e0556ffce748641de6c68fef48e
SHA256: A31E894CA60E0E15F7C16558E7FA9401EA4EDBB48C7015EE841F58C101A5A880
File Size: 1.49 MB, 1485800 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Rockstar Games
  • Siber Systems
  • Zoom Communications, Inc.
File Description
  • RoboForm Installer and Uninstaller
  • Rockstar Games Launcher Redirector
  • Zoom Meetings Installer
File Version
  • 9.7.8.8
  • 6.5.0
  • 1.0.0.98
Internal Name
  • rfwipeout
  • RockstarRedirector.exe
  • Zoom Meetings Installer
Legal Copyright
  • Copyright (C) 1999-2025 Siber Systems Inc.
  • Rockstar Games Inc. (C) 2005-2024 Take Two Interactive. All rights reserved.
  • © Zoom Communications, Inc. All rights reserved.
Original Filename
  • rfwipeout.exe
  • RockstarRedirector.exe
  • Zoom Meetings Installer
Product Name
  • RoboForm
  • Rockstar Games Launcher Redirector
  • Zoom Meetings Installer
Product Version
  • 9.7.8.8
  • 6.5.0
  • 1.0.0.98

Digital Signatures

Signer Root Status
Rockstar Games, Inc. DigiCert Trusted Root G4 Hash Mismatch
VideoLAN DigiCert Trusted Root G4 Hash Mismatch
Zoom Video Communications, Inc. DigiCert Trusted Root G4 Hash Mismatch
Siber Systems Sectigo Public Code Signing Root R46 Hash Mismatch

File Traits

  • golang
  • Installer Version
  • No Version Info
  • x64

Block Information

Total Blocks: 918
Potentially Malicious Blocks: 1
Whitelisted Blocks: 917
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • CobaltStrike.XA
  • EternityLog.A
  • GO.GoCLR.B
  • Go.Agent.F
  • Hive.A
Show More
  • Redline.AI
  • ShellcodeRunner.TA

Files Modified

File Attributes
c:\users\user\downloads\data.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\soul.db Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
Show More
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletionEx
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetIoCompletion
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Network Winsock2
  • WSAStartup

Related Posts

Trending

Most Viewed

Loading...