Trojan

GenPack:Trojan.Agent.DQQD (B) removal tips

Malware Removal

The GenPack:Trojan.Agent.DQQD (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What GenPack:Trojan.Agent.DQQD (B) virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine GenPack:Trojan.Agent.DQQD (B)?


File Info:

name: 713F4FCFB0E631FDBE43.mlw
path: /opt/CAPEv2/storage/binaries/7c09e37656345213fbe14c441b494ffb7e7965b2e1174169705199729ee3c057
crc32: B6B9D1C2
md5: 713f4fcfb0e631fdbe43c1740b108ae0
sha1: c6dcbf4237e00736d56cedeea3dd580782da6bb2
sha256: 7c09e37656345213fbe14c441b494ffb7e7965b2e1174169705199729ee3c057
sha512: 439568a2920829fd605df67b7f665f5c6ddab31ea307b55a2c73c175ede000a85ee5409b86e59d3b900e17e81650f3b07efb0458390594de96bd496baceea3ce
ssdeep: 1536:jxnhmuHsywOKwrpuV9SBNJJb50cJ/Lim5bB3DpWbgE24zX7Zd:FA+lpDJFb5LimpB3Dp4X7Zd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11F93011BE7EB17C5C6444230890BA8FB9E796C5B2001CA67D7F51E2B3D98F593538AB0
sha3_384: 13748205017d31242feecc3581c0c510a74c7b9b1b298e18cfc809096acdb7ba90a4669b468274f70d92d71d3137b8ee
ep_bytes: 60e80000000058055a0b00008b3003f0
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

GenPack:Trojan.Agent.DQQD (B) also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Wabot.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGenPack:Trojan.Agent.DQQD
FireEyeGeneric.mg.713f4fcfb0e631fd
McAfeeGenericRXAA-AA!713F4FCFB0E6
CylanceUnsafe
ZillyaBackdoor.Wabot.Win32.2321
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
AlibabaMalware:Win32/Dorpal.ali1000029
K7GWTrojan ( 0052964f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Backdoor.Wabot.a
CyrenW32/Wabot.K.gen!Eldorado
SymantecW32.Wabot
ESET-NOD32a variant of Win32/Delf.NRF
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Wabot-9783917-0
KasperskyBackdoor.Win32.Wabot.a
BitDefenderGenPack:Trojan.Agent.DQQD
NANO-AntivirusTrojan.Win32.Delf.eqwfrm
AvastWin32:Delf-VKB [Trj]
TencentTrojan.Win32.Wabot.a
SophosML/PE-A + Troj/Luiha-M
ComodoBackdoor.Win32.Wabot.A@4knk5y
DrWebTrojan.MulDrop6.64369
VIPREBehavesLike.Win32.Malware.ssc (mx-v)
TrendMicroBackdoor.Win32.WABOT.SMD
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.nc
EmsisoftGenPack:Trojan.Agent.DQQD (B)
IkarusWin32.Outbreak
JiangminWorm.Generic.gbw
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASBOL.C66A
GridinsoftRansom.Win32.Zbot.sa
MicrosoftBackdoor:Win32/Wabot.A
ZoneAlarmBackdoor.Win32.Wabot.a
GDataGenPack:Trojan.Agent.DQQD
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Wabot.R210508
VBA32Backdoor.Wabot
ALYacGenPack:Trojan.Agent.DQQD
MAXmalware (ai score=87)
MalwarebytesBackdoor.Wabot
TrendMicro-HouseCallBackdoor.Win32.WABOT.SMD
RisingBackdoor.Wabot!8.31C (CLOUD)
YandexBackdoor.Wabot!YyyGDhI33bI
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_81%
FortinetW32/Delf.NRF!tr
BitDefenderThetaAI:Packer.C0D7E7DC20
AVGWin32:Delf-VKB [Trj]
Cybereasonmalicious.fb0e63
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.300983.susgen

How to remove GenPack:Trojan.Agent.DQQD (B)?

GenPack:Trojan.Agent.DQQD (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment