Trojan

Trojan.Agent.GARH removal guide

Malware Removal

The Trojan.Agent.GARH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.GARH virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Agent.GARH?


File Info:

name: 06A533CDF48B3A12F8F1.mlw
path: /opt/CAPEv2/storage/binaries/26ceac5673711cd964c6167d9c1eac661f8bc9ccbed6776d5480d029c2f01415
crc32: AA126EE4
md5: 06a533cdf48b3a12f8f1033530324385
sha1: 9e2796cfe98bff14ecc01db3d0a8e92e9b43336b
sha256: 26ceac5673711cd964c6167d9c1eac661f8bc9ccbed6776d5480d029c2f01415
sha512: e1b7e1d868068c0474e69a6edda9759952b7940902608ec1849eb6ecf45df46532e1dd5792cd27fa2fff3da1e8d01075d2d900a7ee9f0bfb8bde400ad66274a1
ssdeep: 3072:i64TRnltulOuQuT1XwoVXz5cWcOGsLo3JEg+I:ITpgzWZLsLiqI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11774F70273EAA46ED9B277B05EFAD395C633FD259633C21F3284191F5DA1A405E22372
sha3_384: c343c921bd6311746cf34a90d77d0d3991ebf645eb61e800c07bad6cad93dcce81ef0000e7f52877cd53cbe1f275de8b
ep_bytes: 60be007047008dbe00a0f8ff57eb0b90
timestamp: 2012-01-29 21:27:45

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

Trojan.Agent.GARH also known as:

BkavW32.AIDetect.malware1
FireEyeGeneric.mg.06a533cdf48b3a12
McAfeeGenericRXAA-AA!06A533CDF48B
CylanceUnsafe
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 700000111 )
K7GWTrojan ( 700000111 )
Cybereasonmalicious.fe98bf
BitDefenderThetaGen:NN.ZexaF.34698.vu0@aOAgE6ni
CyrenW32/Zusy.MH.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
APEXMalicious
ClamAVWin.Trojan.Generic-9951773-0
AvastWin32:Evo-gen [Trj]
ComodoPacked.Win32.MUPX.Gen@24tbus
VIPRETrojan.Agent.GARH
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.Zapchast.ag
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.50E6
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.4Z5YRN
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Malware-gen.R498458
ALYacTrojan.Agent.GARH
MalwarebytesMalware.AI.392875563
RisingDropper.Generic!8.35E (C64:YzY0Oi0LXJc46yhZ)
IkarusTrojan-Downloader.Win32.Genome
FortinetW32/Zusy.4353!tr
AVGWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan.Agent.GARH?

Trojan.Agent.GARH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment