Trojan

UDS:Trojan.Win32.Garvi (file analysis)

Malware Removal

The UDS:Trojan.Win32.Garvi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan.Win32.Garvi virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine UDS:Trojan.Win32.Garvi?


File Info:

crc32: F8A78F93
md5: 52911f85ff9bf20a7f81ae4a80f8820d
name: 52911F85FF9BF20A7F81AE4A80F8820D.mlw
sha1: a9e0594fbc43d7e9e7e275f3136b3e15e398edc0
sha256: d2db5ffa3b259a3ed4d270ad96a15c008883ecff395eb1aa5816264c8a27a8db
sha512: a44c08f8a717cd6a60a1cb91d1444f68250262e4017c2f7cf16b91b8f69c0c37b245e37b304366ab38026f936c8c559c83aa3474afa55f50c8d63d850d628656
ssdeep: 12288:BM29YJoNeElWR9BBqIWdgracmdwTHglasg8:BM2loEucIggravOgcsg8
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: Wuhan Dongyi Technology Co., Ltd
FileVersion: 1.2.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: x8d62x9a74x51c6x661f
ProductVersion: 1.2.0.0
FileDescription:
Translation: 0x0804 0x03a8

UDS:Trojan.Win32.Garvi also known as:

K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Garvi.4!c
ClamAVWin.Trojan.Generic-6629330-0
ALYacTrojan.GenericKD.37317366
CylanceUnsafe
SangforTrojan.Win32.Garvi.gen
BitDefenderTrojan.GenericKD.37317366
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.5ff9bf
CyrenW32/Ulise.BO.gen!Eldorado
SymantecML.Attribute.HighConfidence
KasperskyUDS:Trojan.Win32.Garvi.gen
AlibabaTrojan:Win32/Garvi.468efc72
MicroWorld-eScanTrojan.GenericKD.37317366
Ad-AwareTrojan.GenericKD.37317366
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis
FireEyeTrojan.GenericKD.37317366
EmsisoftTrojan.GenericKD.37317366 (B)
eGambitUnsafe.AI_Score_90%
Antiy-AVLTrojan/Win32.Garvi
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.Win32.Garvi.gen
GDataTrojan.GenericKD.37317366
McAfeeArtemis!52911F85FF9B
VBA32Trojan.Garvi
MalwarebytesMachineLearning/Anomalous.100%
RisingTrojan.Generic@ML.91 (RDML:BNgAU0kZ4WD1AkQWga/igQ)
YandexTrojan.Garvi!9BjLbgRLLkY
IkarusTrojan.Garvi
MaxSecureTrojan.Malware.74127495.susgen
FortinetW32/Ulise.AOOC!tr

How to remove UDS:Trojan.Win32.Garvi?

UDS:Trojan.Win32.Garvi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment