Trojan

Trojan.Agent.GHNB removal

Malware Removal

The Trojan.Agent.GHNB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.GHNB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.Agent.GHNB?


File Info:

name: 97EE0A50FD1874AF8465.mlw
path: /opt/CAPEv2/storage/binaries/1b4191459fa7ce7ba588a426786b07fa7e9884056a53ced0897c04d1e7cef4d1
crc32: 4B39EA15
md5: 97ee0a50fd1874af84655abdf10bb39e
sha1: d4851acd3b352597c1f4abca2d7bf3835d4362be
sha256: 1b4191459fa7ce7ba588a426786b07fa7e9884056a53ced0897c04d1e7cef4d1
sha512: 2d61d7482ead813d96c70731b273510b85508120946ebcf913c64d3e9039cf82c8030637b177de3a2815c1f9e19bdd7700e67dfbf5b4cff7cf8955154b27fc48
ssdeep: 12288:EH1857Fa2dALbyZa5uHZ/jiaQZKmRuUDm2r+Wg5ukiS6u:RE2dALbyZa5uHZkQmRbVol
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T137159F2138C09172EEF320B747ECBA2682ADE4B4071915DF06D867EED7606C17F36696
sha3_384: 68ff3d93fe386a3270a73de858ea12b135022eba483651e50d9254f722ede927f4b1213b2b0fd335bfeb52346095b986
ep_bytes: e951190400e921890500e9c69f0400e9
timestamp: 2023-10-25 06:33:49

Version Info:

0: [No Data]

Trojan.Agent.GHNB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.SmokeLoader.i!c
DrWebTrojan.SmokeLoader.41
MicroWorld-eScanTrojan.Agent.GHNB
FireEyeTrojan.Agent.GHNB
SkyhighBehavesLike.Win32.Generic.dm
McAfeeRDN/smoke loader
Cylanceunsafe
ZillyaBackdoor.Mokes.Win32.13399
SangforTrojan.Win32.Lumma.swkaa
AlibabaTrojanPSW:Win32/Redline.039459e0
K7GWTrojan ( 005ad94a1 )
K7AntiVirusTrojan ( 005ad94a1 )
VirITTrojan.Win32.Genus.TSI
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HVLV
APEXMalicious
TrendMicro-HouseCallTrojan.Win32.SMOKELOADER.YXDJ1Z
Paloaltogeneric.ml
ClamAVWin.Packed.Pwsx-10012424-0
KasperskyHEUR:Trojan-PSW.Win32.Stealerc.gen
BitDefenderTrojan.Agent.GHNB
NANO-AntivirusTrojan.Win32.SmokeLoader.kcqgvt
AvastWin32:PWSX-gen [Trj]
TencentTrojan-PSW.Win32.Stealerc.kl
EmsisoftTrojan.Agent.GHNB (B)
GoogleDetected
F-SecureHeuristic.HEUR/AGEN.1366785
VIPRETrojan.Agent.GHNB
TrendMicroTrojan.Win32.SMOKELOADER.YXDJ1Z
SophosTroj/Krypt-ABY
IkarusTrojan.Win32.Redline
JiangminTrojan.PSW.Stealerc.mc
VaristW32/Stealer.GD.gen!Eldorado
AviraHEUR/AGEN.1366785
Antiy-AVLTrojan/Win32.Kryptik.hvao
KingsoftWin32.Troj.Unknown.a
MicrosoftTrojan:Win32/Redline.GNF!MTB
ArcabitTrojan.Agent.GHNB
ViRobotTrojan.Win.Z.Kryptik.930816.AE
ZoneAlarmHEUR:Trojan-PSW.Win32.Stealerc.gen
GDataWin32.Trojan.PSE.1G9SPMQ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.CrypterX-gen.R617464
VBA32TrojanPSW.Coins
ALYacTrojan.Agent.GHNB
TACHYONTrojan-PWS/W32.Stealerc.930816
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Chgt.AD
RisingTrojan.SmokeLoader!1.EB50 (CLASSIC)
MAXmalware (ai score=86)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HUKQ!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[stealer]:Win/Stealerc.gen

How to remove Trojan.Agent.GHNB?

Trojan.Agent.GHNB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment