Trojan.Agent.GST
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Popularity Rank: | 5,828 |
| Threat Level: | 80 % (High) |
| Infected Computers: | 907 |
| First Seen: | August 21, 2025 |
| Last Seen: | July 27, 2026 |
| OS(es) Affected: | Windows |
The detection of Trojan.Agent.GST on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, allowing unauthorized access and control. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.
Table of Contents
What Is Trojan.Agent.GST?
Trojan.Agent.GST is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate or harmless. The name "Trojan.Agent.GST" suggests that it is a variant of Trojan horse malware, but the specifics of its origin, behavior, and purpose are not immediately clear without further analysis. Trojans are known for their ability to sneak past security defenses and operate covertly, making them particularly dangerous.
How Trojan.Agent.GST Operates
Generally, Trojan horse malware like Trojan.Agent.GST operates by exploiting vulnerabilities in software or manipulating users into installing it. Once installed, it can perform a variety of malicious actions, including but not limited to, stealing sensitive information, downloading additional malware, or providing backdoor access to the attacker. The exact operation of Trojan.Agent.GST would depend on its specific design and the intentions of its creators, but the end goal is typically to compromise the security of the infected system for financial gain or other malicious purposes.
Symptoms of Infection
Identifying a Trojan infection can be challenging due to its stealthy nature. However, some common symptoms that may indicate the presence of malware like Trojan.Agent.GST include unusual system behavior, such as slow performance, frequent crashes, or unfamiliar programs and icons. Additionally, if you notice unexpected changes to your system settings, unusual network activity, or if your antivirus software alerts you to suspicious activity, it could be a sign of infection. Since Trojans can be designed to operate silently, some infections may not exhibit noticeable symptoms until significant damage has been done.
How to Remove Trojan.Agent.GST
- Enter Safe Mode with Networking: This will help prevent the malware from loading and interfering with the removal process. Restart your computer and enter Safe Mode. This can usually be done by pressing a specific key (such as F8) during boot-up, though this may vary depending on your computer's manufacturer.
- Perform a Full Scan with a Reputable Tool: Use a reputable anti-malware tool, such as SpyHunter, to scan your system for malware. Ensure your antivirus and anti-malware software are up-to-date before running the scan.
- Uninstall Suspicious Programs: Go through your installed programs and remove any that you do not recognize or that were installed around the time you suspect the infection occurred.
- Reset Your Browsers: Resetting browsers like Chrome, Firefox, and Edge can help remove any malicious extensions or settings that the malware may have altered. Each browser has its own process for resetting, which can usually be found in its settings or options menu.
- Reboot and Re-scan: After removal and cleanup, reboot your system and perform another scan to ensure that all traces of the malware have been removed.
Conclusion
Removing Trojan.Agent.GST requires careful and systematic steps to ensure that all components of the malware are eliminated from your system. It is crucial to stay vigilant and maintain good cybersecurity practices to prevent future infections. Keeping your operating system, software, and security tools up-to-date, avoiding suspicious downloads and links, and regularly scanning your system for malware can significantly reduce the risk of infection. If you are unsure about any part of the removal process, consider seeking help from a cybersecurity professional to ensure your system is thoroughly cleaned and protected.
Analysis Report
General information
| Family Name: | Trojan.Agent.GST |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
f4d7d69321bd16cd3faa274e96752572
SHA1:
f70b4c9f4c5f2d3181d562d634772f8715501297
SHA256:
B11B32E207523117FB3AF2DB47C95F5130005E42590F1A48C7884C261CFDA329
File Size:
407.55 KB, 407552 bytes
|
|
MD5:
4613a02215a9be06e9ebd0731adf8160
SHA1:
e828999e80e08563a3ecd9e7b08e23af3c315996
SHA256:
A9DFA88341AFA733C0BD9C62047A5D0586B7FBAB8F88A2DB8EAF7DFF43D4AC0C
File Size:
410.62 KB, 410624 bytes
|
|
MD5:
669413460644d71d8a10fa24f07abcd5
SHA1:
6138b1383e3f7a40c3c50d618d804ee28d1c3b96
SHA256:
83BF12D2E745FB1FF37A6CFE92AFFE0E0B2A8A63B37DAB6076C9F557AD0AC8F2
File Size:
339.97 KB, 339968 bytes
|
|
MD5:
87b135cca0628d416c24450dbec8ce01
SHA1:
d404cc65291ae2f317b9035d16467b052dd569dd
SHA256:
AF16E1FC7997CC643198814961D13A2242395A277D1AB1EC00C6E0E87F2A3B70
File Size:
407.55 KB, 407552 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have exports table
- File doesn't have security information
- File is 64-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Traits
- No Version Info
- ntdll
- WriteProcessMemory
- x64
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 1,328 |
|---|---|
| Potentially Malicious Blocks: | 21 |
| Whitelisted Blocks: | 1,251 |
| Unknown Blocks: | 56 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Agent.THB
- Trojan.Agent.Gen.DBU
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| \device\namedpipe\dav rpc service | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| \device\namedpipe\pshost.134133675750261927.1036.defaultappdomain.powershell | Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288 |
| \device\namedpipe\pshost.134187677452290626.7476.defaultappdomain.powershell | Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288 |
| \device\namedpipe\wkssvc | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\__psscriptpolicytest_adk4hnqr.ick.ps1 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\__psscriptpolicytest_ewz1g5ok.tm3.psm1 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\__psscriptpolicytest_huxasi5j.i1a.psm1 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\__psscriptpolicytest_sifjslu3.uwx.ps1 | Generic Write,Read Attributes |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 띀ྃ觞ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | ���O��� | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
13 additional items are not displayed above. |
| Process Manipulation Evasion |
|
| Process Shell Execute |
|
| Anti Debug |
|
| User Data Access |
|
| Encryption Used |
|
| Other Suspicious |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
powershell -Command "Add-MpPreference -ExclusionProcess 'powershell.exe'"
|