Malware

Downloader.Win32.Agent.mqkv removal instruction

Malware Removal

The Downloader.Win32.Agent.mqkv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Agent.mqkv virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • A process attempted to delay the analysis task.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

How to determine Downloader.Win32.Agent.mqkv?


File Info:

crc32: E6D5EC04
md5: bad691e3443f637c381b9150cb183541
name: BAD691E3443F637C381B9150CB183541.mlw
sha1: e4782c47563e869f8bb20d0b8e62d17db306b4d1
sha256: bbe43f04c61977cbf39be76177fe774fe97ccdfeac316d3605574d7921a52f45
sha512: a5d583cf5d71a2b3e70d649fbc7c55639f3c83ed75efe1568dcfcde60be9be5693acd35a6b8a808c2bca4d7247a5a0005d7bb3395d840e4782298fd22765ec60
ssdeep: 24576:dBl42roeU4In8pMy0bkizYYfscLLG3xqFDoQ4ISa0Tde:d7MxBjYYEcLLZFDNSBde
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018
InternalName: FastDownloader.exe
FileVersion: 3.2.0.8
CompanyName: -
ProductName: x8f6fx4ef6x4e0bx8f7dx5668
ProductVersion: 3.2.0.8
FileDescription:
OriginalFilename: FastDownloader.exe
Translation: 0x0804 0x04b0

Downloader.Win32.Agent.mqkv also known as:

Elasticmalicious (high confidence)
DrWebAdware.Downware.19825
CynetMalicious (score: 100)
ALYacGen:Variant.Application.Graftor.928385
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaDownloader:Win32/DownWare.e414d9bf
Cybereasonmalicious.3443f6
CyrenW32/Application.QZYT-8232
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:DropperX-gen [Drp]
Kasperskynot-a-virus:Downloader.Win32.Agent.mqkv
BitDefenderGen:Variant.Application.Graftor.928385
NANO-AntivirusTrojan.Win32.Graftor.iphmfw
MicroWorld-eScanGen:Variant.Application.Graftor.928385
Ad-AwareGen:Variant.Application.Graftor.928385
SophosGeneric ML PUA (PUA)
ComodoPacked.Win32.MUPX.Gen@24tbus
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.bad691e3443f637c
EmsisoftGen:Variant.Application.Graftor.928385 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Adware.Gen
AviraADWARE/DownWare.AW
eGambitUnsafe.AI_Score_95%
MicrosoftPUA:Win32/Downer
GridinsoftAdware.Agent.sd!c
GDataGen:Variant.Application.Graftor.928385
AhnLab-V3PUP/Win32.RL_Downloader.R367892
McAfeeGenericRXAA-AA!BAD691E3443F
MAXmalware (ai score=70)
VBA32Downloader.Agent
MalwarebytesPUP.Optional.ChinAd
PandaTrj/Genetic.gen
RisingAdware.Downloader!1.CB5D (CLOUD)
IkarusPUA.RiskWare.Downer
FortinetRiskware/Downer.DD89
AVGWin32:DropperX-gen [Drp]

How to remove Downloader.Win32.Agent.mqkv?

Downloader.Win32.Agent.mqkv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment