Trojan

Trojan.Agent.GBIZ (B) removal tips

Malware Removal

The Trojan.Agent.GBIZ (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.GBIZ (B) virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Agent.GBIZ (B)?


File Info:

name: C8AFFA016810092541A6.mlw
path: /opt/CAPEv2/storage/binaries/3f604e752a87fed4c1666e2f7c96373fa18cd0534eb38adf4a0ba7192097fff0
crc32: 0E362E58
md5: c8affa016810092541a6f60428899ff2
sha1: f52fe86a613f2f863a55fff65a7de8952f774c73
sha256: 3f604e752a87fed4c1666e2f7c96373fa18cd0534eb38adf4a0ba7192097fff0
sha512: 82f07c1b4ca38798102baafb72295fbb486f26352bcda57efde1bff8becce34d5c930dd151586fc2cfc3d8c55385b5e76b5959e85f72595b9d33dc9b2c332034
ssdeep: 3072:i64TRnltulOuQuT1XweO0VXz5AYHOGsLo3JEg+I:ITpPEzqMLsLiqI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16474F70373EAA46ED9B277B05EFAD3958633FD259633C21F3284191F5DA0A414E217B2
sha3_384: 62b8a45ae02b64521b1c23d8de5761e40d1aee42fcc1470c4944a91a27d4ae23790ef272837f1c69886d1ceed49cb2fb
ep_bytes: 60be007047008dbe00a0f8ff57eb0b90
timestamp: 2012-01-29 21:27:45

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

Trojan.Agent.GBIZ (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Agent.GBIZ
FireEyeGeneric.mg.c8affa0168100925
ALYacTrojan.Agent.GBIZ
CylanceUnsafe
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 700000111 )
K7GWTrojan ( 700000111 )
Cybereasonmalicious.a613f2
CyrenW32/Zusy.MH.gen!Eldorado
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Generic-9951773-0
BitDefenderTrojan.Agent.GBIZ
AvastWin32:Evo-gen [Trj]
Ad-AwareTrojan.Agent.GBIZ
SophosGeneric ML PUA (PUA)
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureTrojan.TR/Dropper.Gen
VIPRETrojan.Agent.GBIZ
Trapminemalicious.high.ml.score
EmsisoftTrojan.Agent.GBIZ (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.4Z5YRN
JiangminTrojan.MSIL.Zapchast.ag
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.50E6
ArcabitTrojan.Agent.GBIZ
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
AhnLab-V3Malware/Win.Malware-gen.R498458
Acronissuspicious
McAfeeGenericRXAA-AA!C8AFFA016810
MAXmalware (ai score=83)
MalwarebytesMalware.AI.392875563
RisingDropper.Generic!8.35E (C64:YzY0Oi0LXJc46yhZ)
IkarusTrojan-Downloader.Win32.Genome
MaxSecureTrojan.Malware.184534397.susgen
FortinetW32/Zusy.4353!tr
BitDefenderThetaGen:NN.ZexaF.34784.vu0@aOAgE6ni
AVGWin32:Evo-gen [Trj]

How to remove Trojan.Agent.GBIZ (B)?

Trojan.Agent.GBIZ (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment