Trojan

Trojan.Agent.ARGY removal instruction

Malware Removal

The Trojan.Agent.ARGY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.ARGY virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Agent.ARGY?


File Info:

name: F32F290409D874FEDB9E.mlw
path: /opt/CAPEv2/storage/binaries/c8d2460484e14b1ee9a06e512aabdffc0e93210a5e06cdad180817aae3f9f1aa
crc32: FD1648FF
md5: f32f290409d874fedb9e7abff5494496
sha1: 2dbbdf9bb0252e202c07fc296692c6044baa3509
sha256: c8d2460484e14b1ee9a06e512aabdffc0e93210a5e06cdad180817aae3f9f1aa
sha512: 77b7c838b0c24b15c996d7d5318e4836ea3cc8ddf7968ae3bb16a05dd1a0e5a8289b051ac4b01dc1086f48f719aa3ec8c4abf500a72d2f8919fde888f11fce0c
ssdeep: 1536:tJuYKwU/vWsEXE0I/ipOpVQXilhf9rqdej:2YxUGffI/cFQt9ecj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FA53DF26E0A66021D2A2E33546E249D2877DFDD88763ED32835206178BD30A58DDEFD7
sha3_384: 3e9c33b05605a269286739d3ef28700a619eabe0989db05d74915a318e0575c742e6dd35c78969f5e76e1a3e45070978
ep_bytes: 558bece8821900008b3508a0410001ce
timestamp: 2009-06-04 22:05:34

Version Info:

Comments:
CompanyName: ComponentOne LLC
FileDescription: hdDrWeb For Windows jB 2011
FileVersion: 5.0.572.1152
InternalName: Dr.Web for Windows
LegalCopyright: Copyright (C) 1g DoctorWeb, Ltd., 1992-2011
LegalTrademarks:
OriginalFilename: PE-PROTECTEDg.exe
ProductName: Dr.Web for Windows J
ProductVersion: 5.0.572.1152
Translation: 0x0419 0x04e3

Trojan.Agent.ARGY also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.CodecPack.m31i
AVGWin32:Downloader-FXR [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.ARGY
FireEyeGeneric.mg.f32f290409d874fe
CAT-QuickHealTrojan.Renos.LX
SkyhighBehavesLike.Win32.Expiro.kc
McAfeeDownloader-CEW.x
MalwarebytesTrojan.Agent
ZillyaTrojan.FakeAV.Win32.45362
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 002056d81 )
AlibabaRiskWare:Win32/FlashApp.0d35b81c
K7GWTrojan ( 002056d81 )
Cybereasonmalicious.409d87
VirITTrojan.Win32.Generic.CKOA
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.FakeAlert.BBT
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:Downloader-FXR [Trj]
ClamAVWin.Trojan.FakeAV-14042
KasperskyHoax.Win32.FlashApp.cmvn
BitDefenderTrojan.Agent.ARGY
NANO-AntivirusTrojan.Win32.Jorik.bvtve
TencentMalware.Win32.Gencirc.10bae703
EmsisoftTrojan.Agent.ARGY (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen3
DrWebTrojan.Siggen2.22680
VIPRETrojan.Agent.ARGY
TrendMicroTROJ_FAKEAV.SM1C
Trapminemalicious.high.ml.score
SophosMal/FakeAV-IZ
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Jorik.djw
WebrootTrojan.Downloader:Win32.Renos
VaristW32/FakeAlert.KN.gen!Eldorado
AviraTR/Crypt.XPACK.Gen3
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Skor
KingsoftWin32.NotVirus.FlashApp.a
MicrosoftTrojanDownloader:Win32/Renos.PT
XcitiumTrojWare.Win32.Trojan.Agent.fe@2rtvzl
ArcabitTrojan.Agent.ARGY
ViRobotTrojan.Win32.Jorik.65024
ZoneAlarmHoax.Win32.FlashApp.cmvn
GDataTrojan.Agent.ARGY
GoogleDetected
AhnLab-V3Trojan/Win32.FakeAV.R2894
Acronissuspicious
VBA32TScope.Malware-Cryptor.SB
ALYacTrojan.Agent.ARGY
TACHYONTrojan/W32.Jorik.65024
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_FAKEAV.SM1C
RisingDownloader.Renos!8.1D0 (TFE:2:7mwBO9KeRlF)
YandexTrojan.DL.FakeAlert!pAuvD91GEro
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.1692439.susgen
FortinetW32/Krypt.QKV!tr
BitDefenderThetaGen:NN.ZexaF.36802.dq0@a0BoMWki
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudSypWare:Win/FakeAlert.BBT

How to remove Trojan.Agent.ARGY?

Trojan.Agent.ARGY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment