Spy Trojan

TrojanSpy:Win32/Agent.GS information

Malware Removal

The TrojanSpy:Win32/Agent.GS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Agent.GS virus can do?

  • Sample contains Overlay data
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to bypass application controls using the squiblydoo technique
  • Creates a copy of itself
  • Deletes executed files from disk
  • Created a service that was not started
  • Uses suspicious command line tools or Windows utilities

How to determine TrojanSpy:Win32/Agent.GS?


File Info:

name: 74F8FF81E9BD4630619D.mlw
path: /opt/CAPEv2/storage/binaries/4366919de284174c2f803a48374b60ffddc3638780f8ab54120f08f90c7fc546
crc32: 3A1CDCB9
md5: 74f8ff81e9bd4630619dcae6aa5fe43a
sha1: 3c0d1b346872a25d995d106fd967d832b8d88204
sha256: 4366919de284174c2f803a48374b60ffddc3638780f8ab54120f08f90c7fc546
sha512: dde344ec8d6c8d1515186a9de3df79f0ae6b2187179f0bd22b7af3daae30e5319c3053694350022bedab42c392bbbd2543a233874d01faa1a54b3e7b05d293ee
ssdeep: 1536:LFivstt0ekRRg6Jj5qesYQfAYM5k65ax/xGf149KRYJlX1ln+ahMzqVQfD4EAY:zrkw6DqUha249KRClX1lvEuWD4k
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T127C38D126AD35CA9CD24C5BB9C5ED136D772BC5256208AC713107A4F3F32392DA2AE4F
sha3_384: 3b912d5d8266acbae91191606712affe58c8a3abe23374e6d78b90f73af3c00c5f18db7ebd32f0b37deff5f371f894e9
ep_bytes: 558bec6aff68c86a400068705b400064
timestamp: 2009-01-06 15:03:23

Version Info:

0: [No Data]

TrojanSpy:Win32/Agent.GS also known as:

MicroWorld-eScanGen:Variant.Midie.110907
ClamAVWin.Malware.Midie-10002850-0
CAT-QuickHealW32.Xloader.A4
McAfeeW32/Kavsp
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 001081931 )
K7GWVirus ( 001081931 )
Cybereasonmalicious.1e9bd4
VirITTrojan.Win32.Agent.AVLA
CyrenW32/Agent.IQ.gen!Eldorado
SymantecW32.Pavsee.A
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.NAK
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Agent.cm
BitDefenderGen:Variant.Midie.110907
NANO-AntivirusTrojan.Win32.Agent.bfccdz
AvastWin32:Agent-ADPP [Trj]
TencentTrojan.Win32.Lamer.af
EmsisoftGen:Variant.Midie.110907 (B)
F-SecureTrojan.TR/Downloader.Gen
DrWebWin32.HLLO.Mokl.4
VIPREGen:Variant.Midie.110907
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.74f8ff81e9bd4630
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Midie.110907
JiangminWin32/Agent.f
AviraTR/Downloader.Gen
MAXmalware (ai score=84)
XcitiumTrojWare.Win32.Trojan.Agent.Gen@1t6j3f
ArcabitTrojan.Midie.D1B13B
ZoneAlarmVirus.Win32.Agent.cm
MicrosoftTrojanSpy:Win32/Agent.GS
GoogleDetected
AhnLab-V3Trojan/Win32.Mulcler.R7598
BitDefenderThetaAI:Packer.2F5698C620
ALYacGen:Variant.Midie.110907
VBA32BScope.Trojan.Agent
Cylanceunsafe
PandaTrj/Genetic.gen
RisingSpyware.Agent!8.C6 (TFE:5:xOpyo7pyGMD)
YandexTrojan.GenAsa!bwCQYZ/Nz6M
IkarusTrojan-Dropper.Agent
MaxSecureVirus.W32.Lamer.hq
FortinetW32/Agent.AZU!tr
AVGWin32:Agent-ADPP [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanSpy:Win32/Agent.GS?

TrojanSpy:Win32/Agent.GS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment