Adware

How to remove “Adware.Agent.QBU”?

Malware Removal

The Adware.Agent.QBU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Agent.QBU virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Authenticode signature is invalid

How to determine Adware.Agent.QBU?


File Info:

name: E4C9194CCBFF806F4F26.mlw
path: /opt/CAPEv2/storage/binaries/4bf65187a6b45e481e5b3e93480fc8b2e43c58394a8a50565d53e8e2cf4e4f1a
crc32: 150455E2
md5: e4c9194ccbff806f4f263b325ed13d42
sha1: 61766c206d692c60764b9ec1a150b30eff173e8c
sha256: 4bf65187a6b45e481e5b3e93480fc8b2e43c58394a8a50565d53e8e2cf4e4f1a
sha512: 7b19aa1be1b9339a247e79531acd37e738f6b38334514802c8575619d147262190203dddfb8fbf9df85ba0da404eb55f8e210e8058f3fbefc75b90b6c2ef0f33
ssdeep: 6144:rx7U8bW1mVSEWIMiraaZAkqDbyBclE0plWX1+j63t:rtBbs8paWAkqD6cy0LM+G3t
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BCB46B01FF508072D47103368AAB5B26B73DBA211B2707C7A7D81A7D9E71BC06F71A66
sha3_384: a5129abe448704d4839a4041353f6f5e78be02a55911d31d1bb47c4b75b83f9c21ccc477c768e304cc9f2bd4f5bcb8a6
ep_bytes: e8f8b30000e97ffeffffe8c26600008b
timestamp: 2015-11-15 12:22:03

Version Info:

0: [No Data]

Adware.Agent.QBU also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.Linkury.2!c
MicroWorld-eScanAdware.Agent.QBU
FireEyeGeneric.mg.e4c9194ccbff806f
ALYacAdware.Agent.QBU
MalwarebytesPUP.Optional.Linkury
SangforPUP.Win32.Linkury.8
K7AntiVirusAdware ( 004d74fa1 )
AlibabaAdWare:Win32/Linkury.096c398f
K7GWAdware ( 004d74fa1 )
Cybereasonmalicious.ccbff8
VirITTrojan.Win32.Generic.CKKI
CyrenW32/S-19416760!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Toolbar.Linkury.AC potentially unwanted
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Adware.Agent-1356442
Kasperskynot-a-virus:AdWare.Win32.Linkury.ih
BitDefenderAdware.Agent.QBU
NANO-AntivirusRiskware.Win32.Linkury.dzbudz
SUPERAntiSpywarePUP.Linkury/Variant
AvastFileRepMalware [PUP]
TencentMalware.Win32.Gencirc.10b7af3e
Ad-AwareAdware.Agent.QBU
SophosGeneric PUA GB (PUA)
ComodoApplication.Win32.Linkury.AC@61ysql
DrWebAdware.Linkury.56
ZillyaAdware.CrossRider.Win32.30376
McAfee-GW-EditionBehavesLike.Win32.Generic.gm
EmsisoftAdware.Agent.QBU (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.GenericKD.hm
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1228553
KingsoftWin32.Troj.Agent.v.(kcloud)
MicrosoftProgram:Win32/Occamy.AA
ViRobotAdware.Linkury.497152.J
GDataWin32.Adware.Pirax.A
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.Toolbar.R168346
McAfeeAdware-Linkury
MAXmalware (ai score=99)
VBA32Adware.Linkury
CylanceUnsafe
RisingTrojan.Win32.Generic.1941EF41 (C64:YzY0OjgE1kN47wxPFczl768B3V8)
YandexTrojan.GenAsa!MmNXqifqAQE
IkarusPUA.Toolbar.Linkury
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Linkury
BitDefenderThetaGen:NN.ZexaE.34638.EuW@a41WZNfi
AVGFileRepMalware [PUP]
PandaTrj/Genetic.gen
CrowdStrikewin/grayware_confidence_90% (W)

How to remove Adware.Agent.QBU?

Adware.Agent.QBU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment