Trojan

About “GenPack:Trojan.Agent.DQQD” infection

Malware Removal

The GenPack:Trojan.Agent.DQQD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What GenPack:Trojan.Agent.DQQD virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine GenPack:Trojan.Agent.DQQD?


File Info:

name: AEDDB1B594F512C6AE8A.mlw
path: /opt/CAPEv2/storage/binaries/8b8d3f85b49a74d44284b34556ecfa4f7808fbdf60c3308fa18cef5cfe841c94
crc32: 932D72A9
md5: aeddb1b594f512c6ae8a412c5885404c
sha1: 2ffa6bc11d32f28e92d3eed2265da3e3a8ac4632
sha256: 8b8d3f85b49a74d44284b34556ecfa4f7808fbdf60c3308fa18cef5cfe841c94
sha512: 4b928d207f083b29ad7ece3f029c3309c691e2c3a8917d7922999e4af34e4e39e94efcbcf822e3f301b7e1195dc95fc645e2ee3080d7b3113c62d7a273484ade
ssdeep: 196608:rZCIzmcbEi9pR6cPIjZ1B4QouKtJZjNxnFClZtCyEjm7PogH7jNoNPU:NmeR/6cQ15cLfnaZtdEyToA7j0U
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E0B6330C365D9DBCD03E51386057864FE96935A03346AA2EEEF4D6D38A2B4FC0D446FA
sha3_384: 2d4141b54e982073a3bcce3c78d9bc7dc1eba2a85bcaebd82d076ab50b5980eb0510ddf9aca9e50371a8eb6138ca170c
ep_bytes: 60e80000000058055a0b00008b3003f0
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

GenPack:Trojan.Agent.DQQD also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGenPack:Trojan.Agent.DQQD
FireEyeGeneric.mg.aeddb1b594f512c6
McAfeeGenericRXAA-AA!AEDDB1B594F5
CylanceUnsafe
VIPREBehavesLike.Win32.Malware.ssc (mx-v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
BitDefenderGenPack:Trojan.Agent.DQQD
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.594f51
BitDefenderThetaAI:Packer.FB60C6DA1D
CyrenW32/Trojan.GPL.gen!Eldorado
SymantecW32.Wabot
ESET-NOD32a variant of Win32/Delf.NRF
BaiduWin32.Backdoor.Wabot.a
TrendMicro-HouseCallBackdoor.Win32.WABOT.SMD
AvastWin32:Zbot-LV [Trj]
ClamAVWin.Trojan.Wabot-7053120-0
KasperskyBackdoor.Win32.Wabot.a
RisingWorm.Chilly!1.661C (CLASSIC)
SophosML/PE-A
ComodoBackdoor.Win32.Wabot.A@4knk5y
DrWebTrojan.MulDrop6.64369
ZillyaBackdoor.Wabot.Win32.2310
TrendMicroBackdoor.Win32.WABOT.SMD
McAfee-GW-EditionBehavesLike.Win32.Backdoor.vc
SentinelOneStatic AI – Malicious PE
EmsisoftGenPack:Trojan.Agent.DQQD (B)
APEXMalicious
JiangminWorm.Generic.gbw
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASBOL.C66A
MicrosoftBackdoor:Win32/Wabot.A
GDataWin32.Trojan.PSE.MIA95L
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win.Wabot.R431896
Acronissuspicious
VBA32Backdoor.Wabot
MalwarebytesBackdoor.Wabot
TencentTrojan.Win32.Wabot.a
YandexBackdoor.Wabot!9XOZJESPPLY
MAXmalware (ai score=84)
FortinetW32/Delf.NRF!tr
AVGWin32:Zbot-LV [Trj]
CrowdStrikewin/malicious_confidence_60% (D)
MaxSecureBackdoor.W32.Wabot.A

How to remove GenPack:Trojan.Agent.DQQD?

GenPack:Trojan.Agent.DQQD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment