Trojan

How to remove “Trojan.Agent.GBIZ”?

Malware Removal

The Trojan.Agent.GBIZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.GBIZ virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Agent.GBIZ?


File Info:

name: A275522B4D19CFA4EEED.mlw
path: /opt/CAPEv2/storage/binaries/0a4616ce15ae5a47daa9dd4505cf342002bfbf8f479e973bc5289985313d8927
crc32: D43F32B0
md5: a275522b4d19cfa4eeed044332b18255
sha1: 58ff3ebb9b0f17a00c974f2cca44136835faa21e
sha256: 0a4616ce15ae5a47daa9dd4505cf342002bfbf8f479e973bc5289985313d8927
sha512: ec8e4dff6a6b437109826498cc5d9a36b862c3103ae3613baf84a8218d0f4afc354cbfac0b23043220ba5402c192a12c22ba9c064061722275b97244fa4e66e5
ssdeep: 3072:i64TRnltulOuQuT1Xw00VXz5H8POGsLo3JEg+I:ITp0EzNYLsLiqI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17174E60373EAA46ED8B277B05EFAD3958633FD259633C21F3284195F5DA0A405E22772
sha3_384: 0712bb4dc0e0c06d3c6a033c6cb0f88157487f59b0d4a3d9a6f369222e45a6044ef1d3f8d317f0c45700c6490db7be4d
ep_bytes: 60be007047008dbe00a0f8ff57eb0b90
timestamp: 2012-01-29 21:27:45

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

Trojan.Agent.GBIZ also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Agent.GBIZ
FireEyeGeneric.mg.a275522b4d19cfa4
McAfeeGenericRXAA-AA!A275522B4D19
CylanceUnsafe
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 700000111 )
K7GWTrojan ( 700000111 )
Cybereasonmalicious.b9b0f1
BitDefenderThetaGen:NN.ZexaF.34784.vu0@aOAgE6ni
CyrenW32/Zusy.MH.gen!Eldorado
ClamAVWin.Trojan.Generic-9951773-0
BitDefenderTrojan.Agent.GBIZ
CynetMalicious (score: 100)
AvastWin32:Evo-gen [Trj]
Ad-AwareTrojan.Agent.GBIZ
SophosGeneric ML PUA (PUA)
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureTrojan.TR/Dropper.Gen
VIPRETrojan.Agent.GBIZ
SentinelOneStatic AI – Malicious PE
Trapminemalicious.high.ml.score
EmsisoftTrojan.Agent.GBIZ (B)
APEXMalicious
GDataWin32.Trojan.PSE.4Z5YRN
JiangminTrojan.MSIL.Zapchast.ag
AviraTR/Dropper.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.50E6
ArcabitTrojan.Agent.GBIZ
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
AhnLab-V3Malware/Win.Malware-gen.R498458
Acronissuspicious
ALYacTrojan.Agent.GBIZ
MalwarebytesMalware.AI.392875563
RisingDropper.Generic!8.35E (C64:YzY0Oi0LXJc46yhZ)
IkarusTrojan-Downloader.Win32.Genome
MaxSecureTrojan.Malware.184534397.susgen
FortinetW32/Zusy.4353!tr
AVGWin32:Evo-gen [Trj]

How to remove Trojan.Agent.GBIZ?

Trojan.Agent.GBIZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment