Adware

Adware.Agent.YIQ removal guide

Malware Removal

The Adware.Agent.YIQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Agent.YIQ virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Adware.Agent.YIQ?


File Info:

name: 71622792D1B4A8988E96.mlw
path: /opt/CAPEv2/storage/binaries/b562dd212ae7fbe82b653f8b7ce586bfc762c72df9f6d9802af57b22eedbc600
crc32: A848E042
md5: 71622792d1b4a8988e9622d20286842f
sha1: f8a725cf06affaf4af9ab88b2d79ef55a08547ba
sha256: b562dd212ae7fbe82b653f8b7ce586bfc762c72df9f6d9802af57b22eedbc600
sha512: 25d6b264a27fc98d7e7bc11f096c828514d6d8d9a568a10e8e7b6a766943b2f5cff3894a7e9049b90d192bf4309f2bfff38ba66bd91be101660de682dd8fb2e0
ssdeep: 49152:Dc5p/i1+y/IN60fq6wdRUnFEhfu55+6wsZy/5JWWk/kBgYhvAjI3fy9eiSWLspsl:SstID5K3/5JW9IgY9I1ZgL+QhpA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T107568C01E791413DFDF712B346BE712E463CFA60071990DBB28429EA9A357E23D36297
sha3_384: a3435a4ea09cd241fff8e5f788d4eb883274c34accbf8f06bfe67758a98ef0c7da17d47187db1e3f0dde3266814c9f96
ep_bytes: e986261000e9f1ad1200e9bc591200e9
timestamp: 2021-03-16 14:06:44

Version Info:

CompanyName:
FileDescription: Ulttreedit Professiont Teat/Hat Editor
FileVersion: 2.7.5.2
InternalName: Hat Editor
LegalCopyright: IDBM Computer Soot, Inc. 2020 RecordInfo
ProductName: Hat Editor
ProductVersion: 2.7.5.2
LegalTrademarks: Hat Editor
Translation: 0x0804 0x04b0

Adware.Agent.YIQ also known as:

BkavW32.AIDetect.malware2
LionicRiskware.Win32.Generic.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanAdware.Agent.YIQ
FireEyeGeneric.mg.71622792d1b4a898
CAT-QuickHealPUA.IgenericRI.S23894229
McAfeePUP-XPN-JD
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 0058c9cb1 )
AlibabaAdWare:Win32/KuwanBar.9ff8b1f5
K7GWAdware ( 0058c9cb1 )
Cybereasonmalicious.f06aff
BitDefenderThetaGen:NN.ZexaF.34606.@R1@ai6TjKgj
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Agent.NUZ
TrendMicro-HouseCallTROJ_GEN.R002C0PC822
Kasperskynot-a-virus:AdWare.Win32.KuwanBar.ap
BitDefenderAdware.Agent.YIQ
NANO-AntivirusRiskware.Win32.Adware.hknpfz
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.10cf22a6
Ad-AwareAdware.Agent.YIQ
EmsisoftAdware.Agent.YIQ (B)
F-SecureAdware.ADWARE/Agent.zobjg
ZillyaAdware.Agent.Win32.164431
TrendMicroTROJ_GEN.R002C0PC822
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
SophosGeneric PUA PI (PUA)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.KuwanBar.ak
AviraADWARE/Agent.zobjg
MAXmalware (ai score=64)
Antiy-AVLTrojan/Generic.ASMalwS.32D9A83
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
ViRobotAdware.Agent.6152224.BF
GDataAdware.Agent.YIQ
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.R372710
Acronissuspicious
VBA32BScope.Adware.KuwanBar
ALYacAdware.Agent.YIQ
MalwarebytesPUP.Optional.ChinAd
RisingTrojan.Ymacco!8.11BE1 (RDMK:cmRtazr9g3uqjsPrp0Y2hoOVXHU5)
IkarusPUA.Agent
MaxSecureTrojan.Malware.77294178.susgen
FortinetRiskware/Agent
AVGWin32:Adware-gen [Adw]
PandaTrj/GdSda.A

How to remove Adware.Agent.YIQ?

Adware.Agent.YIQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment