Malware

How to remove “RAR/Agent.DA”?

Malware Removal

The RAR/Agent.DA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RAR/Agent.DA virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Executed a process and injected code into it, probably while unpacking
  • A process was set to shut the system down when terminated
  • Installs itself for autorun at Windows startup
  • Exhibits behavior characteristic of Nanocore RAT
  • Creates a hidden or system file
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
strongods.ddns.net

How to determine RAR/Agent.DA?


File Info:

crc32: 0528B1F4
md5: f5764533c2cca7a21006da61f98b12fb
name: tmpip1zayof
sha1: 4d9aca2e03cef121e48d1f7fbbc8ec45939a0f31
sha256: c0722d0e58ef57301d0883dcddf27c8eed901c9a01b186e6b400c48f7ff6a832
sha512: 0c4ce6a6cebad7327f4b36f9d2a06a9717e359d672bf1d7db26420d5e0de005888f918859fb9e1a3c23884b10b3cbbfd05b906e5ead227e40891ab789256edb3
ssdeep: 24576:6NA3R5drXstXueQHYY5d29XaDEai1s+ka5fvLyBtEC9:z5MXkYG0qgai1sY5X2BSA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

RAR/Agent.DA also known as:

MicroWorld-eScanTrojan.GenericKD.43232443
FireEyeGeneric.mg.f5764533c2cca7a2
CAT-QuickHealTrojan.Wacatac
ALYacTrojan.GenericKD.43232443
CylanceUnsafe
K7AntiVirusTrojan ( 000121231 )
AlibabaTrojan:RAR/Generic.78531d3e
K7GWTrojan ( 000121231 )
Cybereasonmalicious.e03cef
Invinceaheuristic
F-ProtW32/MalitRAR.A.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32RAR/Agent.DA
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Autoit-7600991-0
GDataTrojan.GenericKD.43232443
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.43232443
Paloaltogeneric.ml
ViRobotTrojan.Win32.Z.Malitrar.1065502
RisingTrojan.Pack-RAR!1.BB61 (CLASSIC)
Ad-AwareTrojan.GenericKD.43232443
SophosMal/MalitRar-I
F-SecureDropper.DR/AutoIt.Gen
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.WACATAC.THEBHBO
McAfee-GW-EditionBehavesLike.Win32.Suspicioustrojan.tc
EmsisoftTrojan.GenericKD.43232443 (B)
CyrenW32/MalitRAR.A.gen!Eldorado
WebrootW32.Trojan.Gen
Aviraiinip.exe
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D293ACBB
AegisLabTrojan.BAT.Crypter.tqa8
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Ymacco.AAA2
CynetMalicious (score: 100)
McAfeeArtemis!F5764533C2CC
MAXmalware (ai score=80)
MalwarebytesTrojan.Dropper.SFX
ZonerProbably Heur.RARAutorun
TrendMicro-HouseCallTrojan.Win32.WACATAC.THEBHBO
TencentWin32.Trojan.Generic.Ectq
IkarusTrojan.Inject
FortinetW32/Generic.DA!tr
MaxSecureTrojan.Malware.102028383.susgen
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_70% (W)
Qihoo-360Generic/HEUR/QVM06.3.827D.Malware.Gen

How to remove RAR/Agent.DA?

RAR/Agent.DA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment