Trojan

AIT:Trojan.Agent.CUQV removal tips

Malware Removal

The AIT:Trojan.Agent.CUQV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Agent.CUQV virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine AIT:Trojan.Agent.CUQV?


File Info:

name: 07A58429AE2041BD4624.mlw
path: /opt/CAPEv2/storage/binaries/cc363f110ae8ffb1c185f9173390860c51fef90f3f3fd48d77549ea215ba086c
crc32: 79185730
md5: 07a58429ae2041bd46244354ce3cbb3e
sha1: 75d22b093c2634dd48335e25ff9de708dfd187f0
sha256: cc363f110ae8ffb1c185f9173390860c51fef90f3f3fd48d77549ea215ba086c
sha512: 66b89fae84535958fb95858b37b36ca14bf8cdae44d5682ae8a9161f84dc17a51621db1e837c63fcbfd1d174b1c3d776206c9ce5ab12321fe6ed73856f611e06
ssdeep: 6144:6ysoB9OlwXdln8rp3ZC7X0aeJIKeVq7yVuNJBolW99T2Ck9q/hXP38Tz5:6qxXipAXQt+VurKW99TNk9q/hA5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17584115189A5CC79E2A17774D03BCC851E657C71CEE07BA88B75E02EE839783A507E0E
sha3_384: 9bbb0eea20a560a4cc88f4646243cca6eef6306bf1019d68952c6857fdc760bb6e3542e2db74a3659360f69afb0d1710
ep_bytes: 60be008048008dbe0090f7ff57eb0b90
timestamp: 2018-02-06 12:20:27

Version Info:

Translation: 0x0809 0x04b0

AIT:Trojan.Agent.CUQV also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanAIT:Trojan.Agent.CUQV
FireEyeGeneric.mg.07a58429ae2041bd
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderAIT:Trojan.Agent.CUQV
ArcabitAIT:Trojan.Agent.CUQV
BitDefenderThetaAI:Packer.076B800815
VirITTrojan.Win32.MulDrp.BCXV
SymantecTrojan Horse
ESET-NOD32a variant of Generik.FAQPSFG
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/XPACK.b5c459d3
NANO-AntivirusTrojan.Win32.Mlw.eyvigl
RisingTrojan.Generic!8.C3 (CLOUD)
Ad-AwareAIT:Trojan.Agent.CUQV
SophosMal/Generic-S
ZillyaTrojan.Generic.Win32.340812
TrendMicroTROJ_GEN.R002C0OIG21
EmsisoftAIT:Trojan.Agent.CUQV (B)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
GDataAIT:Trojan.Agent.CUQV (3x)
CynetMalicious (score: 100)
VBA32Trojan-Downloader.Autoit.gen
ALYacAIT:Trojan.Agent.CUQV
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0OIG21
TencentWin32.Trojan.Generic.Glp
YandexTrojan.Agent!PWEx0GewQEg
FortinetAutoIt/TrojanDownloader.OKK!tr.dldr
AVGWin32:Malware-gen
Cybereasonmalicious.9ae204
Paloaltogeneric.ml

How to remove AIT:Trojan.Agent.CUQV?

AIT:Trojan.Agent.CUQV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment