Spy Trojan

Trojan.Agent.GoldenSpy removal guide

Malware Removal

The Trojan.Agent.GoldenSpy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.GoldenSpy virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • CAPE detected the GoldenSpy malware family

How to determine Trojan.Agent.GoldenSpy?


File Info:

name: 126599DA0C79CE196C96.mlw
path: /opt/CAPEv2/storage/binaries/b6982fe4ab882cfdcba091c6617b9d279a9bcfd3e28a76d5fb2c0cdfc0c23064
crc32: 85F46036
md5: 126599da0c79ce196c960d0ba28aacda
sha1: eec54b7a3921ed35e4709c6f1fdcaf3bf1ce080f
sha256: b6982fe4ab882cfdcba091c6617b9d279a9bcfd3e28a76d5fb2c0cdfc0c23064
sha512: 8ea9a736c0d28fe48503704b108c331fc08e7857a0e36a8ad465a1d9c195a65c1637651677bc6fc495015d05bc36a1a5ddb92a23128763eac9cd03c0ba02a086
ssdeep: 12288:BjFANdfPLaA6r9NZo6PZbqEJeG++mMBXqQ:jAWXJPZbqAeQmMQQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D6A49D14B962C036C5B242314D78EB7681ADB9641F3709EBB3D80A3D6E706D26736E37
sha3_384: bd37a5ef7dd7c49c08b946bfa531fbeb7093c79a2ee433071b7311b45bd8917c561c6682cb59e2df48a6c14964cbbb17
ep_bytes: e8dc080000e974feffff558becff7508
timestamp: 2020-03-27 03:17:32

Version Info:

0: [No Data]

Trojan.Agent.GoldenSpy also known as:

BkavW32.AIDetectMalware
SkyhighBehavesLike.Win32.Generic.gh
ALYacTrojan.Agent.GoldenSpy
ZillyaTrojan.Agent.Win32.1325284
SangforTrojan.Win32.Goldenspy.V89u
K7AntiVirusTrojan ( 00564e581 )
AlibabaTrojan:Win32/GoldenSpy.f96d7d46
K7GWTrojan ( 00564e581 )
SymantecBackdoor.Goldenspy!g1
ESET-NOD32a variant of Win32/Agent.UEL
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Agentb.a
NANO-AntivirusTrojan.Win32.Ulise.hmkoex
SophosMal/Generic-S
F-SecureTrojan.TR/Agent.aka
DrWebTrojan.Siggen9.56857
TrendMicroBackdoor.Win32.GOLDENSPY.YPAH-A
Trapminesuspicious.low.ml.score
JiangminTrojan.Agentb.gwc
WebrootW32.Trojan.Gen
VaristW32/ABTrojan.FESR-9194
AviraTR/Agent.aka
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Agent
ViRobotTrojan.Win32.S.Agent.473880
ZoneAlarmUDS:Trojan.Win32.Agentb.a
GoogleDetected
AhnLab-V3Trojan/Win32.GoldenSpy.R342354
McAfeeTrojan-FSQQ!126599DA0C79
TrendMicro-HouseCallBackdoor.Win32.GOLDENSPY.YPAH-A
TencentWin32.Trojan.Agent.Eplw
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.87187859.susgen
FortinetW32/Agent.UEL!tr
DeepInstinctMALICIOUS

How to remove Trojan.Agent.GoldenSpy?

Trojan.Agent.GoldenSpy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment