Malware

Application.Agent.JRQ removal tips

Malware Removal

The Application.Agent.JRQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Agent.JRQ virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Steals private information from local Internet browsers

How to determine Application.Agent.JRQ?


File Info:

crc32: 1E6986E5
md5: ec0248f794a52aaae15d913b7a9c8c80
name: EC0248F794A52AAAE15D913B7A9C8C80.mlw
sha1: 5dd3d709ac359a3683574d2ac7a1c9fddf2bb57a
sha256: 726766d8400eed9c8dea11478380675c46e8f5065bf48c7a0011eb6cded03157
sha512: a3fe3883ef9f4b8b8c5aa70a06738716a25392815e5e2455bce997da4b974899f0415746c41a3c1bc40099872417bcc020ad84baae62c0203742246b7cb089a0
ssdeep: 12288:gNba9Wotn5pt6hnU7oNWmEGxyutNN0l/oJ6B49Sy7rEDf8mYDna+0jbNkdz:+po5pt6hPNWHVENN0lQBnPEUMWdz
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2021
InternalName: SEMx667ax80fdx4e0bx8f7dx5668.exe
FileVersion: 6.0.0.0322
ProductName: SEMx667ax80fdx4e0bx8f7dx5668.exe
FileDescription: _
OriginalFilename: SEMx667ax80fdx4e0bx8f7dx5668.exe
Translation: 0x0804 0x04b0

Application.Agent.JRQ also known as:

K7AntiVirusAdware ( 0057a7f41 )
Elasticmalicious (high confidence)
DrWebAdware.Qjwmonkey.168
CynetMalicious (score: 100)
ALYacApplication.Agent.JRQ
CylanceUnsafe
ZillyaAdware.Qjwmonkey.Win32.811
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaAdWare:Win32/Qjwmonkey.39ede385
K7GWAdware ( 0057a7f41 )
Cybereasonmalicious.794a52
CyrenW32/Trojan.RUCL-2303
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Qjwmonkey.K
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
Kasperskynot-a-virus:AdWare.Win32.Qjwmonkey.buy
BitDefenderApplication.Agent.JRQ
MicroWorld-eScanApplication.Agent.JRQ
Ad-AwareApplication.Agent.JRQ
SophosGeneric PUA FN (PUA)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPUP-XNV-EJ
FireEyeApplication.Agent.JRQ
EmsisoftApplication.Downloader (A)
SentinelOneStatic AI – Malicious PE
JiangminDownloader.Agent.ohm
WebrootW32.Adware.Gen
AviraADWARE/Qjwmonkey.Gen
eGambitTrojan.Generic
MicrosoftPUA:Win32/Qjwmonkey
GridinsoftTrojan.Qjwmonkey.dd!c
ArcabitApplication.Agent.JRQ
GDataApplication.Agent.JRQ
AhnLab-V3PUP/Win.Qjwmonkey.C4402732
McAfeeGenericRXAA-AA!EC0248F794A5
MAXmalware (ai score=100)
VBA32BScope.Downloader.Agent
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallPUA.Win32.Qjwmonkey.IS
RisingAdware.Downloader!1.BDCA (CLOUD)
YandexPUA.Qjwmonkey!4czo9v7qAzQ
IkarusTrojan.Taranis
MaxSecureTrojan.Malware.121218.susgen
FortinetAdware/Qjwmonkey
AVGWin32:AdwareX-gen [Adw]
Paloaltogeneric.ml

How to remove Application.Agent.JRQ?

Application.Agent.JRQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment