Trojan

What is “Win32/TrojanDownloader.Agent.GHY”?

Malware Removal

The Win32/TrojanDownloader.Agent.GHY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Agent.GHY virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32/TrojanDownloader.Agent.GHY?


File Info:

name: A4EBC6A697D4354585BA.mlw
path: /opt/CAPEv2/storage/binaries/9f197c28abad5ac5ba05d3fa3d34d03ec7443620ace7a325d8be8d6719ee2974
crc32: 369F93EF
md5: a4ebc6a697d4354585ba1807c008de83
sha1: a800a640ea63233661d1258c4e58c9912acd211f
sha256: 9f197c28abad5ac5ba05d3fa3d34d03ec7443620ace7a325d8be8d6719ee2974
sha512: cc58cb8db8c7a7df488e2d375735091cab5fba27f928486900ca99cc1fa6590cd83acfad81da475caf19c319da283d36351a272ac900ff18c9f7bd7f58e8ed4b
ssdeep: 768:Z/JcEvZfn1Ql98Ce8S6c85awfvfGFdkgeskhroIE6P/B8I7JUSiVfVyLA+Kjw7:Z/JccZfKyArowBJ9wo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D8330953A921D8B1F16545B212B60B38B830EA6104FA865BEFC0DEB12DBB735DF6940D
sha3_384: 2a982204f5446432f66cfeeb2f8b4a8e7d849d2e20c81e46f5ac515cb26caa4b6fc0893ca78df2584436d5fc9bcc88a4
ep_bytes: e87b4a0000e8114a000033c0c3909090
timestamp: 2021-08-06 23:14:13

Version Info:

0: [No Data]

Win32/TrojanDownloader.Agent.GHY also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.172530
FireEyeGeneric.mg.a4ebc6a697d43545
McAfeeGenericRXPT-GW!A4EBC6A697D4
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.1B8BA4521E
CyrenW32/Agent.ENH.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.GHY
ClamAVWin.Malware.Doina-9888856-0
KasperskyVHO:Trojan.Win32.Convagent.gen
BitDefenderGen:Variant.Lazy.172530
NANO-AntivirusTrojan.Win32.Dwn.jidwuh
AvastWin32:Trojan-gen
TencentTrojan.Win32.Agentb.wp
Ad-AwareGen:Variant.Lazy.172530
SophosML/PE-A
ComodoPacked.Win32.MUPX.Gen@24tbus
ZillyaTrojan.Agent.Win32.2408779
McAfee-GW-EditionBehavesLike.Win32.Generic.qm
SentinelOneStatic AI – Malicious PE
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Lazy.172530 (B)
IkarusTrojan-Downloader
JiangminTrojan.Agent.dlwp
AviraTR/Crypt.XPACK.Gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.PSE.1ETEWJE
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4548399
ALYacGen:Variant.Lazy.172530
TACHYONTrojan/W32.Convagent.52736
MalwarebytesMalware.AI.4039412793
APEXMalicious
RisingTrojan.Convagent!8.12323 (C64:YzY0OpS2n1706rbh)
MAXmalware (ai score=89)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.FTV!tr.dldr
AVGWin32:Trojan-gen
Cybereasonmalicious.697d43
PandaTrj/GdSda.A

How to remove Win32/TrojanDownloader.Agent.GHY?

Win32/TrojanDownloader.Agent.GHY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment