Malware

Application.Agent.JQQ information

Malware Removal

The Application.Agent.JQQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Agent.JQQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to identify installed AV products by installation directory

How to determine Application.Agent.JQQ?


File Info:

name: A5469E8FBD0A461ABD7A.mlw
path: /opt/CAPEv2/storage/binaries/56dcab021f8b55de90ffdbd7bfee6f259c817815c06df37419b4aae3adda8d75
crc32: 2B7B68DF
md5: a5469e8fbd0a461abd7a24f37d8a8343
sha1: 9b7fe5fa57a2789cb478df84ffb9d1d9e849a537
sha256: 56dcab021f8b55de90ffdbd7bfee6f259c817815c06df37419b4aae3adda8d75
sha512: 6698a2fbc7f884198d2bd508e76bcaa4be109fedddbc184ce13a80c4279ba389beefc8866dfdc3f9057b68779276fd6e51e87aad4b6758ab8af9bfc4efdeba75
ssdeep: 49152:nwjALL495Tveu/JLBMG+MmrFC0CjRnWXzXMf1C0LBxamhBN7M/fmDJo:bwnq2L2Mv0inWDXABvBN7mf0Jo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D7D52303F7D34475F4259C398BE684101C5739FA1FE2705B2DB4EA0E8AB9A818C7AF56
sha3_384: 1b293765ab516f0c6ac6458ed9feb24c903d9014b65c4812254932c5204516fa9237eac2d6c20f0a521b537bbf5942e5
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2016-01-15 08:22:50

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Minus Setup
FileVersion:
LegalCopyright:
ProductName: Minus
ProductVersion: 2.9.3.6
Translation: 0x0000 0x04b0

Application.Agent.JQQ also known as:

LionicAdware.Win32.Vosteran.2!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
FireEyeApplication.Agent.JQQ
McAfeeArtemis!A5469E8FBD0A
MalwarebytesAdware.DownloadAssistant
SangforTrojan.Win32.Wacatac.B
K7AntiVirusTrojan ( 00576e9f1 )
AlibabaTrojan:Win32/Tnega.a3b6eba7
K7GWTrojan ( 00576e9f1 )
Cybereasonmalicious.fbd0a4
CyrenW32/Agent.CTJ.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Adware.Dealalpha-9831447-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderApplication.Agent.JQQ
NANO-AntivirusTrojan.Win32.Kryptik.ilsifv
MicroWorld-eScanApplication.Agent.JQQ
AvastWin32:AdwareX-gen [Adw]
DrWebTrojan.Zadved.1677
VIPRETrojan.Win32.Generic!BT
EmsisoftApplication.Agent.JQQ (B)
GDataApplication.DealAlpha.2.Gen (2x)
AviraHEUR/AGEN.1206258
Antiy-AVLTrojan/Generic.ASMalwS.314CA06
MicrosoftTrojan:Win32/Wacatac.B!ml
MAXmalware (ai score=85)
VBA32Adware.Vosteran
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
FortinetW32/Kryptik.GZFR!tr
AVGWin32:AdwareX-gen [Adw]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Application.Agent.JQQ?

Application.Agent.JQQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment