Backdoor

Backdoor.Agent.ABKQ removal guide

Malware Removal

The Backdoor.Agent.ABKQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Agent.ABKQ virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Agent.ABKQ?


File Info:

crc32: 4D067171
md5: 12a44ab11ff77cb82377719253558d5f
name: 12A44AB11FF77CB82377719253558D5F.mlw
sha1: 2f739c2e3c7a08d3b024f1533698bab17efc2a31
sha256: 204f7a64c1ff20c0651df5c492642e67ad221c090e7cabd5e111d05f286ca04d
sha512: 4aa6bac32cfc399f6d411b7ceb7ec6f429b29f44fb91009d4173fd26f7c929e565a1fa97326eae38fe81b71c750097e416254ab0c809f23c51fb5b77ca425a69
ssdeep: 3072:3FL9a/IbxdBJbEIZvh2oQgw/FWP8aVXdRPnp45AxJI7CMSbD:3Fc/IbAIZvh2oGCjbxJK
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2008
InternalName: x901ax7528x670dx52a1x7a0bx5e8f
FileVersion: 1, 0, 0, 1
ProductVersion: 1, 0, 0, 1
FileDescription: x901ax7528x670dx52a1x7a0bx5e8f
Translation: 0x0804 0x04b0

Backdoor.Agent.ABKQ also known as:

K7AntiVirusTrojan-Downloader ( 0055e3da1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacBackdoor.Agent.ABKQ
CylanceUnsafe
AlibabaTrojanDownloader:Win32/Generic.fee40cf3
K7GWTrojan-Downloader ( 0055e3da1 )
Cybereasonmalicious.11ff77
BaiduWin32.Trojan-Downloader.Agent.iv
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Agent.RWY
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Downloader.Win32.Generic
BitDefenderBackdoor.Agent.ABKQ
NANO-AntivirusTrojan.Win32.Agent.cwodxq
MicroWorld-eScanBackdoor.Agent.ABKQ
TencentTrojan.Win32.Downloader.mge
Ad-AwareBackdoor.Agent.ABKQ
ComodoMalware@#28zjdbr57j12c
BitDefenderThetaGen:NN.ZexaF.34294.hmKfaieUawaj
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.BrowseFox.cc
FireEyeGeneric.mg.12a44ab11ff77cb8
EmsisoftBackdoor.Agent.ABKQ (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Heur
AviraBDS/Agent.ABKQ.1
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2EB5A7
KingsoftWin32.Heur.KVM003.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataBackdoor.Agent.ABKQ
McAfeeGeneric.emv
MAXmalware (ai score=100)
VBA32BScope.Trojan.Wacatac
PandaTrj/CI.A
YandexTrojan.DL.Agent!0hXkutvIlbs
IkarusTrojan-Downloader.Win32.Agent
FortinetRiskware/InstallCore
AVGWin32:Malware-gen

How to remove Backdoor.Agent.ABKQ?

Backdoor.Agent.ABKQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment