Spy Trojan

What is “Trojan:Win32/GoldenSpy.A”?

Malware Removal

The Trojan:Win32/GoldenSpy.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/GoldenSpy.A virus can do?

  • Authenticode signature is invalid
  • CAPE detected the GoldenSpy malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/GoldenSpy.A?


File Info:

name: 72C7004537CD158B0D80.mlw
path: /opt/CAPEv2/storage/binaries/f89e898ea40e10901c0c9f9100f269a227323ace1f7248293bfd57982dea1a67
crc32: 8218E4E6
md5: 72c7004537cd158b0d80f07d65e71f6b
sha1: 8d07cbd90527568c90f6cb481a1a21853c8b2524
sha256: f89e898ea40e10901c0c9f9100f269a227323ace1f7248293bfd57982dea1a67
sha512: 8514eac88531d66e629e1756e7ec5fc41547ddbe2af00dc5ae6c7193f47108864c0487968c1b70e7b4d029da59b2543a34f4a4b5ae7885166bc1c65657c3275f
ssdeep: 12288:QJ9YFdXP8pxf1HUh9P8EUDUJ1eMWoCeM/YTTZJ:GYasn8EUDUDeMGeMiTZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12EB49E15B952C036C57241304D38EB7681AEBA641F374AEB73D80B2D6E706D26B36E37
sha3_384: 2f63e175714876ae25658ab50c001ea9d8d1d340f3624b3e01bdcb4e08df76696c9afa099a2ea9fae228c62a733cb470
ep_bytes: e8dc080000e974feffff558becff7508
timestamp: 2020-03-23 13:05:34

Version Info:

0: [No Data]

Trojan:Win32/GoldenSpy.A also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agentb.4!c
MicroWorld-eScanTrojan.GenericKD.46605357
FireEyeGeneric.mg.72c7004537cd158b
CAT-QuickHealBackdoor.GoldenSpy.S14495536
SkyhighBehavesLike.Win32.AdwareLinkury.hh
McAfeeTrojan-FSQQ!72C7004537CD
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.Agent.Win32.1318383
SangforTrojan.Win32.Agentb.jyib
K7AntiVirusTrojan ( 00564e581 )
AlibabaTrojan:Win32/GOLDENSPY.8cef24af
K7GWTrojan ( 00564e581 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D2C7242D
BitDefenderThetaAI:Packer.83656C2A1F
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.UEL
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Agentb.jyib
BitDefenderTrojan.GenericKD.46605357
NANO-AntivirusTrojan.Win32.Ulise.hnapfo
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan.Agentb.Qcnw
EmsisoftTrojan.GenericKD.46605357 (B)
DrWebTrojan.Siggen9.56860
VIPRETrojan.GenericKD.46605357
TrendMicroBackdoor.Win32.GOLDENSPY.YPAH-A
SophosMal/Generic-R
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agentb.gwc
WebrootW32.Trojan.Gen
GoogleDetected
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Agent
Kingsoftmalware.kb.a.928
MicrosoftTrojan:Win32/GoldenSpy.A
ViRobotTrojan.Win32.S.Agent.516096.JW
ZoneAlarmTrojan.Win32.Agentb.jyib
GDataTrojan.GenericKD.46605357
VaristW32/Trojan.HWQ.gen!Eldorado
AhnLab-V3Trojan/Win32.GoldenSpy.R335573
VBA32BScope.Trojan.Agentb
ALYacTrojan.Agent.Ashify
TACHYONBackdoor/W32.GoldenSpy.516096
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallBackdoor.Win32.GOLDENSPY.YPAH-A
RisingBackdoor.GoldenSpy!1.C82E (CLASSIC)
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.87187890.susgen
FortinetW32/Agent.UEL!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/GoldenSpy.A?

Trojan:Win32/GoldenSpy.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment