Malware

How to remove “Win32:Agent-ARSZ [Trj]”?

Malware Removal

The Win32:Agent-ARSZ [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Agent-ARSZ [Trj] virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Collects information to fingerprint the system

How to determine Win32:Agent-ARSZ [Trj]?


File Info:

crc32: D2E1D946
md5: 1763f7c7fee33b0e448f6c20548ecf9a
name: 1763F7C7FEE33B0E448F6C20548ECF9A.mlw
sha1: 96ec297bd03af02619dc335d708cfd15a2c7cc67
sha256: 8754d177541b5f71894978ddf801019d456d05077e5a55b7352b4a6fa1f3b3f2
sha512: d0b73fe3a5d6d3e1b8f3f8eeaba864452fc51a0611a9831066896bc9a50f3b5ac874b8f4b0256723fda48d1b7af9112a7560335c4adc4d00fd839b0b55f9eb46
ssdeep: 1536:oiHkr71+u8hVlGg2iq2zbOkQCxDihJeZiovzZ4Rot+hd:o8kP1+7h3Gg2iLcCjigz6R6+h
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Win32:Agent-ARSZ [Trj] also known as:

K7AntiVirusTrojan ( 700000121 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader12.61670
CynetMalicious (score: 100)
ALYacGen:Variant.MSILPerseus.2097
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 700000121 )
Cybereasonmalicious.7fee33
BaiduMSIL.Backdoor.Bladabindi.a
CyrenW32/Perseus.U.gen!Eldorado
ESET-NOD32a variant of MSIL/Bladabindi.AT
APEXMalicious
AvastWin32:Agent-ARSZ [Trj]
ClamAVWin.Trojan.Bladabindi-6044420-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.MSILPerseus.2097
NANO-AntivirusTrojan.Win32.Agent.edqjjw
MicroWorld-eScanGen:Variant.MSILPerseus.2097
Ad-AwareGen:Variant.MSILPerseus.2097
SophosML/PE-A + Mal/Bladabi-Q
BitDefenderThetaGen:NN.ZemsilF.34628.fmW@amSLxzf
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Generic.mm
FireEyeGeneric.mg.1763f7c7fee33b0e
EmsisoftGen:Variant.MSILPerseus.2097 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.bchru
AviraTR/Downloader.Gen
eGambitUnsafe.AI_Score_100%
MicrosoftBackdoor:MSIL/Bladabindi.AL
ArcabitTrojan.MSILPerseus.D831
ZoneAlarmHEUR:Trojan.MSIL.Bladabindi.gen
GDataMSIL.Trojan-Spy.Keylogger.9K7WE8
AhnLab-V3Trojan/Win32.Bladabindi.R148214
Acronissuspicious
McAfeeBackDoor-FDCY
MAXmalware (ai score=83)
MalwarebytesBackdoor.Bladabindi
TrendMicro-HouseCallBKDR_BLADABI.SMC
RisingBackdoor.Njrat!1.9E49 (CLASSIC)
IkarusTrojan-Downloader.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.YW!tr
AVGWin32:Agent-ARSZ [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.NjRAT.HwMA7L8A

How to remove Win32:Agent-ARSZ [Trj]?

Win32:Agent-ARSZ [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment