Spy Trojan

How to remove “Trojan.GoldenSpy”?

Malware Removal

The Trojan.GoldenSpy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.GoldenSpy virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Network anomalies occured during the analysis.
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • A process attempted to delay the analysis task by a long amount of time.
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup

How to determine Trojan.GoldenSpy?


File Info:

name: 84FF122838C0DA5AB5DD.mlw
path: /opt/CAPEv2/storage/binaries/885d24d927df6fbc26122975f6ce7ff7b75823e6dafd8137a4e892bac9adce1f
crc32: 0ABD306B
md5: 84ff122838c0da5ab5ddcaa8f45f7011
sha1: 62c57392c0e18b713b76b9084e09eb1f0ef8333a
sha256: 885d24d927df6fbc26122975f6ce7ff7b75823e6dafd8137a4e892bac9adce1f
sha512: 16699a48ce810f4b23db9575c312d87317e5a2ddeb8113afc29bdcbeaa6b836a73b76b6fc8124c47c3a9357e8e0f5a0e598843ca85b103da6a0f7e6c05219fd5
ssdeep: 12288:4MBBXM05pWpYu5MD/cAvHekgyq1yS3M8uXztceYzVTk8p2saMnLTk8p2saMnk:4MBZd5pWpN5M7oyONuXbYZTHTg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D4E4236612C080BED5A444789E7DE736CFFB1181A31D159E934F8CF53A72C2A2F89B19
sha3_384: 69900f59ba0e61c3a17946066b5de65efebf4976de211830e47fac91423794278b3b321da0ec876258eae807eb75ea84
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-06-18 21:33:23

Version Info:

0: [No Data]

Trojan.GoldenSpy also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Goldenspy.4!c
Elasticmalicious (high confidence)
DrWebDLOADER.Trojan
MicroWorld-eScanTrojan.GenericKD.42974804
FireEyeTrojan.GenericKD.42974804
ALYacBackdoor.Agent.Vigorf.A
CylanceUnsafe
SangforTrojan.Win32.Agent.UEL
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/GOLDENSPY.3a995c49
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZexaE.34638.ZuW@aiTK3tfi
CyrenW32/Trojan.JDWJ-1832
SymantecBackdoor.Goldenspy
ESET-NOD32Win32/Agent.UEL
APEXMalicious
Paloaltogeneric.ml
BitDefenderTrojan.GenericKD.42974804
NANO-AntivirusTrojan.Win32.Generic.hsfkbs
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.42974804
SophosMal/Generic-R
TrendMicroBackdoor.Win32.GOLDENSPY.YPAH-A
McAfee-GW-EditionTrojan-FRWL!134D9FFC9C65
EmsisoftTrojan.GenericKD.42974804 (B)
IkarusTrojan.Dropper
JiangminTrojan.Agentb.ldb
WebrootW32.Malware.Gen
AviraTR/Dropper.Gen
ViRobotTrojan.Win32.S.Agent.696722
GDataTrojan.GenericKD.42974804
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win32.GoldenSpy.C4148224
McAfeeArtemis!84FF122838C0
MAXmalware (ai score=99)
VBA32Trojan.Agentb
MalwarebytesTrojan.GoldenSpy
RisingTrojan.Occamy!8.F1CD (CLOUD)
YandexTrojan.Agent!EUvUn3WmSv4
SentinelOneStatic AI – Suspicious PE
FortinetW32/Agent.UEL!tr
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove Trojan.GoldenSpy?

Trojan.GoldenSpy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment