Trojan

Should I remove “Trojan.Agent.GHNB”?

Malware Removal

The Trojan.Agent.GHNB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.GHNB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.Agent.GHNB?


File Info:

name: 62F1833F7AB36D905A71.mlw
path: /opt/CAPEv2/storage/binaries/1130049b135a134f6b5f8bbff1f0b714bd6c8dd8269af53c35bde658816cfb41
crc32: 61C5CE48
md5: 62f1833f7ab36d905a71583f543897db
sha1: 4e884e460ee52c73852476852cf8b9dcce0ca06f
sha256: 1130049b135a134f6b5f8bbff1f0b714bd6c8dd8269af53c35bde658816cfb41
sha512: ab764a783a63467ddbe2fd724defc2681fa5a7cf5bea972d899b33401cd33394b1695ba5131303aa831cfaac873846e89e5f55c44286236d387bfefef5a09cce
ssdeep: 12288:nH1i+DCN2dA/DwZa5uH/p08UnfimFulDm2C+W1NukiSJ:XW2dA/DwZa5uHByamFKVE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E8157D2138C0917AEEF320B74BECBA2642ADE4B4071916DF06D857EED7506C17B32796
sha3_384: 2a4458aba752ab0606facb36c71f1c91f0286769efe988987f8ea54cbd5fb9222f0bf1eb8817fa39d96a552fa7c00dbb
ep_bytes: e951190400e921890500e9c69f0400e9
timestamp: 2023-10-25 02:02:20

Version Info:

0: [No Data]

Trojan.Agent.GHNB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.Y!c
Elasticmalicious (high confidence)
DrWebTrojan.SmokeLoader.41
MicroWorld-eScanTrojan.Agent.GHNB
SkyhighBehavesLike.Win32.Smokeloader.cm
McAfeeRDN/genericimp
Cylanceunsafe
ZillyaBackdoor.Mokes.Win32.13399
K7AntiVirusTrojan ( 005ad0551 )
AlibabaTrojanPSW:Win32/Redline.e3bc63e5
K7GWTrojan ( 005ad94a1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Agent.GHNB
VirITTrojan.Win32.Genus.TSI
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HVLV
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Pwsx-10012424-0
KasperskyHEUR:Trojan-PSW.Win32.Stealerc.pef
BitDefenderTrojan.Agent.GHNB
NANO-AntivirusTrojan.Win32.SmokeLoader.kcqgvt
AvastWin32:PWSX-gen [Trj]
TencentTrojan-PSW.Win32.Stealerc.kl
EmsisoftTrojan.Agent.GHNB (B)
F-SecureHeuristic.HEUR/AGEN.1366785
VIPRETrojan.Agent.GHNB
TrendMicroTROJ_GEN.R023C0DJU23
SophosTroj/Krypt-ABY
JiangminTrojan.PSW.Stealerc.mc
VaristW32/Stealer.GD.gen!Eldorado
AviraHEUR/AGEN.1366785
Antiy-AVLTrojan/Win32.Kryptik.hvao
MicrosoftTrojan:Win32/Redline.GNF!MTB
ZoneAlarmHEUR:Trojan-PSW.Win32.Stealerc.pef
GDataWin32.Trojan.PSE.1G9SPMQ
GoogleDetected
AhnLab-V3Trojan/Win.CrypterX-gen.R617679
VBA32BScope.Backdoor.Agent
ALYacTrojan.Agent.GHNB
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R023C0DJU23
RisingTrojan.SmokeLoader!1.EB50 (CLASSIC)
YandexTrojan.Kryptik!p9FWZxmIWfQ
IkarusTrojan.Win32.Redline
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.HUKQ!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan.Agent.GHNB?

Trojan.Agent.GHNB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment