Malware

Application.Agent.BQI removal

Malware Removal

The Application.Agent.BQI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Agent.BQI virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (28 unique times)
  • Reads data out of its own binary image
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Steals private information from local Internet browsers
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings

Related domains:

mininews.kpzip.com
kyposition.dftoutiao.com
mini2.eastday.com
mini.7654.com
afpmm.alicdn.com
www.nkscdn.com
tajs.qq.com
cdn3.guangsuss.com
tianqi.eastday.com
position.dftoutiao.com
crl3.digicert.com
ocsp.digicert.com
hm.baidu.com
ocsp.globalsign.com
05imgmini.eastday.com
03imgmini.eastday.com
01imgmini.eastday.com
ocsp2.globalsign.com
crl.globalsign.com
07imgmini.eastday.com
00imgmini.eastday.com
06imgmini.eastday.com
04imgmini.eastday.com
08imgmini.eastday.com
09imgmini.eastday.com
02imgmini.eastday.com
01.imgmini.eastday.com
p.tanx.com
eater.xiaoxiangbz.com
hotnews.dftoutiao.com

How to determine Application.Agent.BQI?


File Info:

crc32: 2A4C33BB
md5: cfb71d0e2e315fed068db76b49944716
name: mininews-2.exe
sha1: 697eba00590353ea7c43cfb8d330e70c6ac5c4b3
sha256: afa668bc2cac9cbd95a657b66dfce458a29642e1f3cd8c88b19ee617daff6b32
sha512: 3f4acd5955852dcfe77614723e07a1b9d013647b9eb0623c7895370db3803d648d4875a9aea4282a6b421a609049ebb864b863d41ba67d16dab9dac9c09a21de
ssdeep: 49152:90X9r/s3eQ6XcuM79pGRmCP+Jj3xGQ7N9y31SsFrT:90geKuM79pxCPwxGQ7sb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x4e0ax6d77x5e7fx4e50x7f51x7edcx79d1x6280x6709x9650x516cx53f8
InternalName: mininews
FileVersion: 4.1.7.14
ProductName: x8ff7x4f60x65b0x95fb
ProductVersion: 4.1.7.14
FileDescription: x8ff7x4f60x65b0x95fb
OriginalFilename: x8ff7x4f60x65b0x95fb
Translation: 0x0804 0x04b0

Application.Agent.BQI also known as:

BkavW32.HfsAdware.C51A
DrWebProgram.Kuaizip.1
MicroWorld-eScanApplication.Agent.BQI
CAT-QuickHealDownldr.Sigmal.S2323718
McAfeeAdware-KZip
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 004f7e1c1 )
BitDefenderApplication.Agent.BQI
K7GWAdware ( 004f7e1c1 )
Cybereasonmalicious.e2e315
TrendMicroTROJ_GEN.R002C0PCD20
SymantecAdware.Adpopup
ESET-NOD32a variant of Win32/KuaiZip.B potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0PCD20
Kasperskynot-a-virus:HEUR:AdWare.Win32.KuziTui.gen
AlibabaBackdoor:Win32/KZip.28fe3bee
NANO-AntivirusTrojan.Win32.KuziTui.ezowmv
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.11491600
Endgamemalicious (high confidence)
EmsisoftApplication.Agent.BQI (B)
ComodoApplicUnwnt@#2xm73l9fbzjbv
F-SecurePotentialRisk.PUA/KuaiZip.Gen
ZillyaTrojan.GenericKD.Win32.109541
Invinceaheuristic
McAfee-GW-EditionAdware-KZip
FireEyeGeneric.mg.cfb71d0e2e315fed
SophosGeneric PUA GJ (PUA)
JiangminDownloader.KuziTui.az
WebrootW32.Adware.Gen
AviraPUA/KuaiZip.Gen
FortinetAdware/KZip
Antiy-AVLRiskWare[Downloader]/Win32.KuziTui
ArcabitApplication.Agent.BQI
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.KuziTui.gen
MicrosoftPUA:Win32/KuaiZip
VBA32BScope.Downloader.KuziTui
MAXmalware (ai score=100)
Ad-AwareApplication.Agent.BQI
MalwarebytesAdware.Kuaiba
APEXMalicious
RisingPUF.KuaiZip!8.2F40 (C64:YzY0OmIF4SsnICmh)
YandexPUA.Downloader!
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
GDataApplication.Agent.BQI
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (D)
MaxSecureTrojan.Malware.10619872.susgen

How to remove Application.Agent.BQI?

Application.Agent.BQI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment