Trojan

How to remove “Trojan.Agent.GBYU (B)”?

Malware Removal

The Trojan.Agent.GBYU (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.GBYU (B) virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Agent.GBYU (B)?


File Info:

name: FDD3A8FE26FA659CC4FB.mlw
path: /opt/CAPEv2/storage/binaries/a27b7a1d89460fcb84302a65089fe0f72adf1a9b1e0ac531ed3e9c46807e71c3
crc32: DE253BAD
md5: fdd3a8fe26fa659cc4fbb98b6dfdb6a8
sha1: de47992d69ffa7fe3feaba2601d51ae8a7ae9662
sha256: a27b7a1d89460fcb84302a65089fe0f72adf1a9b1e0ac531ed3e9c46807e71c3
sha512: a27b338bd399c53d41ab8d145885684fc58647c3d9ef5e939d8073e78647a95b3b0c9bc9e786884c046cb94c53a32651e516c49f66ec71f9ccdafc9398ee22f7
ssdeep: 3072:X6pQc+sSxnTrGadgsFqZeo4pwkhUmZr3hPsOraSo:X6p2sSxTrGvsFUejWyZr3hPswaH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12AD3121364D12382C1960B7908B3B23A63E5667C63E4CBA1C3D5727B7C11BBF263E646
sha3_384: 811df7ea9f9c8621d2c50db1e5aa1afaaa2d15bb8ba83ce6a9d0b51c654d0e272c08ff2b958c75b61c6f600ac6fa8219
ep_bytes: 558bec5668040100006808a4420033f6
timestamp: 2015-08-21 10:28:13

Version Info:

0: [No Data]

Trojan.Agent.GBYU (B) also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Shifu.tnsd
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.GBYU
FireEyeTrojan.Agent.GBYU
CAT-QuickHealTrojan.ShifuPMF.S10291657
ALYacTrojan.Agent.GBYU
Cylanceunsafe
ZillyaTrojan.Shifu.Win32.360
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
AlibabaTrojan:Win32/Shifu.195f
K7GWSpyware ( 005228cb1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.MulDrop7.BENL
CyrenW32/S-7a16e605!Eldorado
SymantecW32.Styes
tehtrisGeneric.Malware
APEXMalicious
ClamAVWin.Trojan.Gamarue-9832405-0
KasperskyTrojan-Banker.Win32.Shifu.eph
BitDefenderTrojan.Agent.GBYU
NANO-AntivirusTrojan.WinXX.Shifu.juaqxd
AvastWin32:Shifu-B [Trj]
TencentTrojan.Win32.Shifu.wb
TACHYONBanker/W32.Shifu.139776
EmsisoftTrojan.Agent.GBYU (B)
F-SecureTrojan.TR/AD.Shifu.hifkw
DrWebTrojan.MulDrop7.20629
VIPRETrojan.Agent.GBYU
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SophosTroj/Shifu-F
IkarusSuspectFile
GDataWin32.Trojan-Spy.Shiz.D
JiangminTrojan.Yakes.akc
GoogleDetected
AviraTR/AD.Shifu.hifkw
Antiy-AVLVirus/Win32.Expiro.imp
XcitiumTrojWare.Win32.Spy.Shiz.NCA@8m98i8
ArcabitTrojan.Agent.GBYU
ViRobotTrojan.Win32.Agent.168448.U
ZoneAlarmTrojan-Banker.Win32.Shifu.eph
MicrosoftBackdoor:Win32/Simda!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Shifu.C2756321
Acronissuspicious
McAfeeGenericRXGM-ZQ!FDD3A8FE26FA
MAXmalware (ai score=83)
MalwarebytesShiz.Spyware.Stealer.DDS
PandaTrj/CI.A
RisingTrojan.Shifu!1.A8EF (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Shifu.B!tr
AVGWin32:Shifu-B [Trj]
Cybereasonmalicious.d69ffa
DeepInstinctMALICIOUS

How to remove Trojan.Agent.GBYU (B)?

Trojan.Agent.GBYU (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment