Threat Database Trojans Trojan.Agent.GHDE

Trojan.Agent.GHDE

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 10
First Seen: October 31, 2025
Last Seen: November 14, 2025
OS(es) Affected: Windows

The detection of Trojan.Agent.GHDE on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the integrity of your computer, steal sensitive information, or disrupt its normal functioning. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Agent.GHDE?

Trojan.Agent.GHDE is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate programs. The name "Trojan.Agent.GHDE" suggests that it is a variant of Trojan horse malware, but without more specific information, it's challenging to determine its exact characteristics or behaviors. Generally, Trojans are known for their ability to sneak into systems by masquerading as useful applications, only to unleash their harmful payload once installed.

How Trojan.Agent.GHDE Operates

Like other Trojans, Trojan.Agent.GHDE likely operates by exploiting vulnerabilities in software or manipulating users into installing it. Once inside a system, it can perform a variety of malicious actions, including but not limited to, stealing personal data, installing additional malware, or providing unauthorized access to the infected computer. The specific operations of Trojan.Agent.GHDE would depend on its design and the intentions of its creators, but the end goal is typically to compromise the security and privacy of the affected system.

Symptoms of Infection

The symptoms of a Trojan.Agent.GHDE infection can vary widely, depending on its payload and the actions it is programmed to perform. Common indicators of a Trojan infection include unusual system behavior, such as unexpected pop-ups, slow performance, or unfamiliar programs appearing on the system. In some cases, the infection might not exhibit obvious symptoms, making it difficult for users to detect without the aid of security software.

  • Unexplained changes in system settings or files.
  • Increased network activity without a clear cause.
  • Appearance of unfamiliar or suspicious programs.
  • System crashes or instability.

How to Remove Trojan.Agent.GHDE

  1. Boot your computer in Safe Mode with Networking to limit the malware's ability to interfere with the removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all traces of the malware.
  3. Uninstall any recently installed programs that you do not recognize or that were installed around the time the malware was detected.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot your computer and run another full scan with your anti-malware tool to ensure that all components of the Trojan have been removed.

Conclusion

The removal of Trojan.Agent.GHDE requires careful and immediate action to prevent further damage to your system and to protect your personal data. By following the steps outlined above and maintaining vigilant security practices, such as keeping your operating system and software up to date, using strong antivirus protection, and being cautious with emails and downloads, you can significantly reduce the risk of future malware infections. Remember, prevention and swift action are key to protecting your digital security and privacy.

Analysis Report

General information

Family Name: Trojan.Agent.GHDE
Signature status: No Signature

Known Samples

MD5: 735e436f901acb511cf8a8be68338a56
SHA1: 1945bc73d0a44a1e218f7d4981385d69f712e7a2
SHA256: E707E9372186300292EC4890C8485CA6C287CDBCE55CE6F1C1DCD8A64243B992
File Size: 6.97 MB, 6967309 bytes
MD5: f1087605f954a8e8740ab5636f67ab14
SHA1: c01808190671ac227e26254a4af85292c2bb755f
SHA256: 4651A7021CA5EA50652F7ABA744EDBA0B7EC44FA56CE711570408C73595958D7
File Size: 8.80 MB, 8799600 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Igor Pavlov
File Description 7z Setup SFX
File Version 9.20
Internal Name 7zS.sfx
Legal Copyright Copyright (c) 1999-2010 Igor Pavlov
Original Filename 7zS.sfx.exe
Product Name 7-Zip
Product Version 9.20

File Traits

  • No Version Info
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\adobenotificationhelper.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\adobenotificationhelper.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\config.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\config.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\coresyncinstall.log Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\coresyncinstall.log Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\fruity convolver.nfo Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\fruity convolver.nfo Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\fruity formula controller.fst Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\7zs3dff.tmp\fruity formula controller.fst Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\fruity reeverb 2.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\fruity reeverb 2.png Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\install.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\install.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\license.rtf Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\license.rtf Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\microsoft_vc110_cxxamp_x64.msm Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\microsoft_vc110_cxxamp_x64.msm Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\microsoft_vc120_crt_x64.msm Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\microsoft_vc120_crt_x64.msm Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\microsoft_vc120_debugcxxamp_x64.msm Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\microsoft_vc120_debugcxxamp_x64.msm Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\microsoft_vc120_debugcxxamp_x86.msm Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\microsoft_vc120_debugcxxamp_x86.msm Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\unzip32.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\unzip32.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\vrfauto.h Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\vrfauto.h Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs44c5.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs44c5.tmp\agentactivationruntimestarter.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs44c5.tmp\agentactivationruntimestarter.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs44c5.tmp\config.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs44c5.tmp\config.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs44c5.tmp\install.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs44c5.tmp\install.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs44c5.tmp\wmsyspr9.prx Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs44c5.tmp\wmsyspr9.prx Synchronize,Write Attributes

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

.\Install.exe
config.exe /hdidmrvG "390358" /S

Trending

Most Viewed

Loading...