Threat Database Trojans Trojan.Agent.GHW

Trojan.Agent.GHW

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 5
First Seen: September 3, 2025
Last Seen: April 8, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.GHW on your system indicates a potential security threat that requires immediate attention. This type of threat is categorized as a Trojan, which is a broad term for malicious software that can cause harm to your computer or steal sensitive information. In this report, we will provide an overview of what Trojan.Agent.GHW is, how it operates, its symptoms, and most importantly, how to remove it from your system.

What Is Trojan.Agent.GHW?

Trojan.Agent.GHW is a type of malware that can infect your computer without your knowledge or consent. The term "Trojan" refers to the fact that this type of malware often disguises itself as legitimate software, allowing it to bypass security measures and gain access to your system. Once inside, it can cause a range of problems, from stealing personal data to disrupting system performance.

How Trojan.Agent.GHW Operates

Malware like Trojan.Agent.GHW typically operates by exploiting vulnerabilities in software or tricking users into installing it. Once installed, it can communicate with its creators, allowing them to control the infected computer remotely. This can lead to unauthorized access to sensitive information, installation of additional malware, or even use of the infected computer for malicious activities such as spamming or distributing malware.

Symptoms of Infection

Identifying a Trojan.Agent.GHW infection can be challenging, as it often does not display obvious symptoms. However, you might notice that your computer is running slower than usual, or you might see unexpected pop-ups, unfamiliar programs, or changes in your browser settings. Sometimes, the malware can cause system crashes or prevent certain programs from running properly. Being vigilant about these signs can help in early detection and removal of the threat.

How to Remove Trojan.Agent.GHW

  1. Boot your computer in Safe Mode with Networking. This will limit the malware's ability to interfere with the removal process and allow you to download necessary tools.
  2. Perform a full scan of your system using a reputable anti-malware tool such as SpyHunter. These tools are designed to detect and remove malware, including Trojans like Trojan.Agent.GHW.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time the malware was detected. Be cautious and only remove programs you are sure are not needed.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings. This can help remove any malicious extensions or settings changes made by the malware.
  5. Reboot your computer and perform another full scan to ensure that all traces of the malware have been removed. This step is crucial to confirm that the removal was successful and that your system is clean.

Conclusion

Removing Trojan.Agent.GHW from your system requires careful steps to ensure that all components of the malware are eliminated. By following the guidance provided, you can effectively remove this threat and protect your computer and personal data from further harm. Remember, prevention is key; keeping your software up to date, using strong antivirus programs, and being cautious when downloading and installing software can significantly reduce the risk of future infections.

Analysis Report

General information

Family Name: Trojan.Agent.GHW
Signature status: Hash Mismatch

Known Samples

MD5: e8f18ad76aba343f5176113ab890c1d4
SHA1: 7df223c136d0e7f823fd5169e2abf95aa8569f33
SHA256: BD8C5DB460A665AB669E6C8D695319DF68035B6E72A17EDF17C086CD9E3FB1A0
File Size: 2.39 MB, 2385136 bytes
MD5: 668c2b45ab7e74d36a514290599088eb
SHA1: d70c1b8373887df80f3652654895c5dfa0c14436
SHA256: 32CFFF30D6ED1F3395B8FFBC8319FAD8723F71547364A6CDE2FADDB2B80B5B1D
File Size: 2.06 MB, 2062928 bytes
MD5: b633c10826ade41fb2029c0ec6abb6c7
SHA1: e751470bec5c7c1e42fc89d3dc48ed51aba4074f
SHA256: DEC46207A352D2B8F21B6EE5698FE4C45C56CD09B2C13FFDA28736C60BABCDFB
File Size: 2.12 MB, 2123896 bytes
MD5: e66b896882f72d5011371b1eb296a594
SHA1: 52586243e0e11b8621c1d69347a77420be60b659
SHA256: 22ACA3698972EBB96A70D9EF2131BCF9718F74C99A904FC285BFD4798D32DC92
File Size: 2.16 MB, 2164920 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • DBSofts
  • Epic Games, Inc.
  • Surfshark
File Description
  • Easy Anti-Cheat Service (EOS)
  • ESF Database Migration Toolkit
  • Surfshark Installer
File Version
  • 2022.3.41.1022081
  • 12.2.0.9
  • 5.16.1999
Internal Name
  • Easy Anti-Cheat Service (EOS)
  • ESF Database Migration Toolkit
  • SurfsharkSetup
Legal Copyright
  • (c) 2005-2024 Unity Technologies. All rights reserved.
  • Copyright (C) 2025 Surfshark
  • Copyright (C) DBSofts Inc
  • Copyright Epic Games, Inc. All Rights Reserved.
Original File Name SurfsharkSetup.exe
Original Filename DMTW.exe
Product Name
  • Easy Anti-Cheat Service (EOS)
  • ESF Database Migration Toolkit
  • Surfshark
Product Version
  • 2022.3.41f1 (0f988161febf)
  • 12.2.0.9
  • 5.16.1999
  • 1.4.0

Digital Signatures

Signer Root Status
Mooii Tech co.,ltd. Class 3 Public Primary Certification Authority Hash Mismatch
EasyAntiCheat Oy GlobalSign Code Signing Root R45 Hash Mismatch
Surfshark B.V. GlobalSign Code Signing Root R45 Hash Mismatch
Huang Qinyin SSL.com Code Signing Intermediate CA ECC R2 Hash Mismatch

File Traits

  • 2+ executable sections
  • golang
  • HighEntropy
  • Installer Version
  • x64

Block Information

Total Blocks: 556
Potentially Malicious Blocks: 0
Whitelisted Blocks: 556
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.GHW
  • GoBot
  • GoBot.B
  • Injector.GSF

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryTimerResolution
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimerResolution
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState

Trending

Most Viewed

Loading...