Trojan

Trojan.Garvi removal instruction

Malware Removal

The Trojan.Garvi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Garvi virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Trojan.Garvi?


File Info:

name: F00E4A94B9FD5F409A68.mlw
path: /opt/CAPEv2/storage/binaries/3d64521072bcee6b4cb5665172d82dfce1f59cdf1a30f4e8ee39ae9fd23e7fa6
crc32: 5DEC383A
md5: f00e4a94b9fd5f409a682d68f3ced69c
sha1: 5bd50452dd244d139e45056b8516b25ec32f8be3
sha256: 3d64521072bcee6b4cb5665172d82dfce1f59cdf1a30f4e8ee39ae9fd23e7fa6
sha512: 784281fbfe33ddf0beb129980715b641ee6fb4a8bab57c17df411f606973c58ca96add19d1cafe674182584e5f1a10981a88d3042e0cc13701e115221a0cfd00
ssdeep: 12288:Npjd5B3w+aZJK8DX6iwf8qg7j48Up8ximQwjmT4eEO+E/yUMqy:NJbpavV7Cf3ZdBomMe0E61qy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T182456C22F2908833C1721D398C5B9EA49BBDBD016A286D6737E63F4C6F7964379152C3
sha3_384: 6f4504b1e84a05290480c2f858a883e4f5bc8bac6c6b93fffca1fb5a8ab62692e5934409670d587eca4cc83d7fc7ecd8
ep_bytes: 558bec83c4f0b8308c4900e894d3f6ff
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Wuhan Dongyi Technology Co., Ltd
FileDescription:
FileVersion:
InternalName:
LegalCopyright: Wuhan Dongyi Technology Co., Ltd
LegalTrademarks:
OriginalFilename:
ProductName: 赢驴准星
ProductVersion: 2023.510.1725.1535
Comments:
Translation: 0x0804 0x03a8

Trojan.Garvi also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Garvi.4!c
FireEyeGeneric.mg.f00e4a94b9fd5f40
McAfeeGenericRXRD-UJ!F00E4A94B9FD
Cylanceunsafe
ZillyaTrojan.Garvi.Win32.2482
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Garvi.437e6ef0
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.4b9fd5
CyrenW32/Ulise.BO.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Garvi.gen
NANO-AntivirusTrojan.Win32.Garvi.jmvnag
AvastFileRepMalware [Misc]
TencentMalware.Win32.Gencirc.10bb27b2
TACHYONTrojan/W32.DP-Garvi.1248256
F-SecureTrojan.TR/Garvi.wizix
TrendMicroTROJ_GEN.R002C0PGO23
McAfee-GW-EditionBehavesLike.Win32.ObfuscatedPoly.tt
SophosMal/Generic-S
AviraTR/Garvi.wizix
Antiy-AVLTrojan/Win32.Garvi
MicrosoftTrojan:Win32/Fareit!ml
ViRobotTrojan.Win.Z.Garvi.1248256.E
ZoneAlarmHEUR:Trojan.Win32.Garvi.gen
GDataWin32.Trojan.Agent.CD58NX
GoogleDetected
AhnLab-V3Malware/Win.UJ.C5459389
VBA32Trojan.Garvi
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PGO23
RisingTrojan.Generic@AI.87 (RDMK:q9OOtE5y4/QKaF2pg9PPBA)
IkarusTrojan.Garvi
MaxSecureTrojan.Malware.74127495.susgen
FortinetW32/Ulise.AOOC!tr
AVGFileRepMalware [Misc]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan.Garvi?

Trojan.Garvi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment