Trojan

What is “Trojan.Agent.GGFV”?

Malware Removal

The Trojan.Agent.GGFV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.GGFV virus can do?

  • A file was accessed within the Public folder.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Agent.GGFV?


File Info:

name: B590A1A34CA01CCCF88A.mlw
path: /opt/CAPEv2/storage/binaries/8e29507d45a77ca3e220a47d08fdb3bc432242cce0ec2b83a548d7a7d1514bcb
crc32: 1687B875
md5: b590a1a34ca01cccf88a4cc0bc3fd98e
sha1: 37fe869ecf1dda2e6a0bd12a0194f8c2ff1097d1
sha256: 8e29507d45a77ca3e220a47d08fdb3bc432242cce0ec2b83a548d7a7d1514bcb
sha512: 62245163f8c7e9416180a265a542bbcd3e648348a51d65bbef55b1cea0cc65b21750a4f92a3bc36433c6704d6404dd09356c29019eb6395e0bd9bc5998b7a0ce
ssdeep: 6144:mhS4fHJEhZ9xgHBWzKzx2tFcXMesKae1so6Hu+jjxRqvNb45J1AWb8GFEyyyyqjK:yS4fHGHghWc1sL2bqJXFEyyyyqjjX2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T116D4D8F364C0E121EA838139D752E9BFE4360CD4DF9D46E3A3D4B91D38B61952B39286
sha3_384: 7f02064559500d94bec59583b3cdaabb71c5a25fd107d3762c79603890cf6d13753b9b4880666a7a9516515461f08e2c
ep_bytes: e8a6ca0000e916feffff8b44240485c0
timestamp: 2023-08-21 09:20:35

Version Info:

CompanyName:
FileDescription: VC6_IN_VM_2 Microsoft 基础类应用程序
FileVersion: 1, 0, 0, 1
InternalName: VC6_IN_VM_2
LegalCopyright: 版权所有 (C) 2023
LegalTrademarks:
OriginalFilename: VC6_IN_VM_2.EXE
ProductName: VC6_IN_VM_2 应用程序
ProductVersion: 1, 0, 0, 1
Translation: 0x0804 0x04b0

Trojan.Agent.GGFV also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agentb.X!c
MicroWorld-eScanTrojan.Agent.GGFV
FireEyeTrojan.Agent.GGFV
ALYacTrojan.Agent.GGFV
MalwarebytesTrojan.Downloader
SangforDownloader.Win32.Agent.V9oj
CrowdStrikewin/malicious_confidence_70% (W)
K7GWTrojan-Downloader ( 005aa4951 )
K7AntiVirusTrojan-Downloader ( 005aa4951 )
ArcabitTrojan.Agent.GGFV
BitDefenderThetaGen:NN.ZexaF.36662.Nq0@auc4nMej
CyrenW32/ABRisk.YMTT-4634
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Agent.HDN
APEXMalicious
CynetMalicious (score: 99)
KasperskyHEUR:Trojan-Downloader.Win32.Agentb.gen
BitDefenderTrojan.Agent.GGFV
AvastWin32:DropperX-gen [Drp]
RisingTrojan.Generic@AI.97 (RDML:subN8zc/vTEeU95WbKVQgg)
EmsisoftTrojan.Agent.GGFV (B)
F-SecureTrojan.TR/Dldr.Agent.cpfis
VIPRETrojan.Agent.GGFV
TrendMicroTROJ_GEN.R002C0XHQ23
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
JiangminTrojanDownloader.Agentb.dh
AviraTR/Dldr.Agent.cpfis
Antiy-AVLTrojan[Downloader]/Win32.Agentb
MicrosoftTrojan:Script/Phonzy.A!ml
ZoneAlarmHEUR:Trojan-Downloader.Win32.Agentb.gen
GDataTrojan.Agent.GGFV
GoogleDetected
McAfeeArtemis!B590A1A34CA0
MAXmalware (ai score=82)
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0XHQ23
TencentMalware.Win32.Gencirc.11b5ab6b
MaxSecureTrojan.Malware.74430235.susgen
FortinetW32/Agent.HDN!tr.dldr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS

How to remove Trojan.Agent.GGFV?

Trojan.Agent.GGFV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment