Trojan

How to remove “Trojan.Agent.GHYM”?

Malware Removal

The Trojan.Agent.GHYM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.GHYM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Agent.GHYM?


File Info:

name: 8708559198076FAD4B6E.mlw
path: /opt/CAPEv2/storage/binaries/90319e033f8835480b1079ab893c0989c33930e9fc75e18236ca0422e3d56033
crc32: 0F14BAB7
md5: 8708559198076fad4b6e7001123b058c
sha1: bc67c96d54b3901ca6d0e0b62bbb53f65276b149
sha256: 90319e033f8835480b1079ab893c0989c33930e9fc75e18236ca0422e3d56033
sha512: 3a5a0fd9b4654517f3746daea68d99077cb61dce9de75d7f17db31c08ddddb7aba5d2fd8662c8518e2928934a0f01b3f24020851016840252872b7fafb60923a
ssdeep: 98304:Ek1oxCETmhIbAFflG/w8+Rc2PnSpJ1V/agwQqZUha5jtSyZIUb:Er4ETEIvYtSpJ1V/2QbaZtli
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T164769D01EBF8DE1ED5BF0375A8B221158BF5F8D1DB53DB9E6900B0AD7A923406942363
sha3_384: 312292a7bc56fce73f549fc9e8a00e620b68a402026b7d951dd4fcd8517ecc38aae66476307631bc49d01abf00c2f7bc
ep_bytes: 60be8756a23701f601f061b8aa296d1b
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Agent.GHYM also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Agent.GHYM
FireEyeTrojan.Agent.GHYM
SkyhighBehavesLike.Win32.Generic.wh
McAfeeGenericRXAA-FA!870855919807
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0057fe481 )
K7GWTrojan ( 0057fe481 )
ArcabitTrojan.Agent.GHYM
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.ECAV
CynetMalicious (score: 100)
APEXMalicious
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderTrojan.Agent.GHYM
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Tiggre.ka
EmsisoftTrojan.Agent.GHYM (B)
VIPRETrojan.Agent.GHYM
TrendMicroPAK_Xed-10
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Copak.cylc
VaristW32/Copak.F.gen!Eldorado
XcitiumPacked.Win32.MUPX.Gen@24tbus
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmVHO:Trojan.Win32.Copak.gen
GDataTrojan.Agent.GHYM
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R554362
BitDefenderThetaGen:NN.ZexaF.36792.@pZ@aGXXzDe
ALYacTrojan.Agent.GHYM
MAXmalware (ai score=87)
VBA32Trojan.Copak
MalwarebytesTrojan.MalPack.Generic
PandaTrj/Genetic.gen
TrendMicro-HouseCallPAK_Xed-10
RisingTrojan.Injector!1.E280 (CLASSIC)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenKryptik.CRNJ!tr
AVGWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Agent.GHYM?

Trojan.Agent.GHYM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment