Malware

AdWare.Win32.Agent.inqg removal tips

Malware Removal

The AdWare.Win32.Agent.inqg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.Agent.inqg virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Suspicious wmic.exe use was detected

How to determine AdWare.Win32.Agent.inqg?


File Info:

name: B7F1801847A4A7308B3C.mlw
path: /opt/CAPEv2/storage/binaries/65391651d0269b329201f2708e78281129bbb6b4fd4c168c75b4f24fb3ca6962
crc32: CEB2A244
md5: b7f1801847a4a7308b3cdae3cac98146
sha1: e969f74940265f6012658c6f0cd891cb9a582693
sha256: 65391651d0269b329201f2708e78281129bbb6b4fd4c168c75b4f24fb3ca6962
sha512: 2da89c31cdc697400194189df4906699569e900a54ad37b9f0e4f98d8baa684629ecf60a080f1230c002719c065d024bc8654f0131e7085ea87c3704a0f924fd
ssdeep: 6144:8e342cMiJfhocE7dQdD3Gsbb9EqkziJfhCcE7dQdAkVX:V4poSdasbhjpCSdAkVX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17434121DBAC489C7D3C982300173F7A9E27E46DA52565A0F0FDC5FAA372B0091951BEB
sha3_384: f679f72cbf4769eee350e570a39faf8b2ca669588f121745f73e4da395a144d331615fd4dd4f467991249b1c7f863356
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

FileVersion: 1.1.9.15053
Translation: 0x0000 0x04e4

AdWare.Win32.Agent.inqg also known as:

BkavW32.AIDetectMalware
FireEyeGeneric.mg.b7f1801847a4a730
K7AntiVirusAdware ( 004c3a9a1 )
K7GWAdware ( 004c3a9a1 )
Cybereasonmalicious.940265
CyrenW32/Trojan.TCZR-4051
Elasticmalicious (high confidence)
ESET-NOD32Win32/Vittalia.Z potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.Win32.Agent.inqg
NANO-AntivirusRiskware.Win32.Agent.ebauvh
SUPERAntiSpywareAdware.ConvertAd/Variant
F-SecureHeuristic.HEUR/AGEN.1339501
DrWebTrojan.Vittalia.138
TrendMicroPUA_VITALIA.component
McAfee-GW-EditionBehavesLike.Win32.Suspicious.dc
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
JiangminAdware.Agent.aol
WebrootPua.Gen
AviraHEUR/AGEN.1339501
Antiy-AVLTrojan/Win32.Wacatac
ZoneAlarmnot-a-virus:AdWare.Win32.Agent.inqg
MicrosoftPUA:Win32/Presenoker
GoogleDetected
VBA32AdWare.Agent
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallPUA_VITALIA.component
RisingPUF.Presenoker!8.F608 (TFE:5:bO7ovX5wo9R)
YandexTrojan.GenAsa!PT76oCd3c5M
FortinetNSIS/Agent.LVIV!tr
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (D)

How to remove AdWare.Win32.Agent.inqg?

AdWare.Win32.Agent.inqg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment