Trojan

How to remove “MemScan:Trojan.Clicker.Agent.ADQ”?

Malware Removal

The MemScan:Trojan.Clicker.Agent.ADQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MemScan:Trojan.Clicker.Agent.ADQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine MemScan:Trojan.Clicker.Agent.ADQ?


File Info:

name: 9C5759AB86C1B2759C8B.mlw
path: /opt/CAPEv2/storage/binaries/b99a36ce9bf6266db6ce330c32096f68ba9d6b75badd1c02aa670093ef60aa7d
crc32: 65F65D14
md5: 9c5759ab86c1b2759c8b600d7bc7cb8b
sha1: 0b6b3d6f3276b1292450027f401c617bc92469c5
sha256: b99a36ce9bf6266db6ce330c32096f68ba9d6b75badd1c02aa670093ef60aa7d
sha512: 488def739f880c8136fc381abb3f79c5e34f22965a06fdd4496afe2a9493cc225720a32e3c69ce8fd0a8c2bd97b1d8688ea27f16fd5a3b393bcdb8274e1f33e1
ssdeep: 768:T4wO7XBz+5Qm3W0tYdrQZHV4EWuWEUOg4jjfS3XJxoXyQ5LBlxBVZ1B+iMiSG9aB:cLXB65939tY6HBg4sXJklxRD9K
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B423CF2E3BC0C8F7D9970A7106775779E3B7E3512263165B2B641F7E2A212C3C92A183
sha3_384: 6b49c1fc4afc7dc3930269ad6273f1822278204b32104e2cdb97934f7334ff35bf142394ab551fab71cc3c805084fb1d
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-06-06 21:41:48

Version Info:

0: [No Data]

MemScan:Trojan.Clicker.Agent.ADQ also known as:

LionicTrojan.Win32.Agent.8!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanMemScan:Trojan.Clicker.Agent.ADQ
FireEyeMemScan:Trojan.Clicker.Agent.ADQ
McAfeeArtemis!9C5759AB86C1
CylanceUnsafe
VIPREMemScan:Trojan.Clicker.Agent.ADQ
K7AntiVirusTrojan-Downloader ( 004618e41 )
BitDefenderMemScan:Trojan.Clicker.Agent.ADQ
K7GWTrojan-Downloader ( 004618e41 )
Cybereasonmalicious.b86c1b
ArcabitTrojan.Clicker.Agent.ADQ
BaiduBAT.Trojan-Clicker.Small.c
CyrenW32/Risk.CGOH-4192
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Trojan.Agent-563271
KasperskyTrojan-Clicker.Win32.Agent.rkr
AlibabaTrojanClicker:Win32/CLICKER.3b833052
NANO-AntivirusTrojan.Win32.Agent.cphql
RisingTrojan.Occamy!8.F1CD (TFE:3:a9gmHl5pCFP)
Ad-AwareMemScan:Trojan.Clicker.Agent.ADQ
SophosMal/Generic-S
ComodoMalware@#32ibh6xlw8tqb
F-SecureMalware.BAT/Clicker.C
DrWebTrojan.DownLoad2.46842
TrendMicroTROJ_CLICKER.RS
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.ph
EmsisoftMemScan:Trojan.Clicker.Agent.ADQ (B)
IkarusTrojan.Win32.TrojanClicker
JiangminTrojanClicker.Agent.dmo
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1233758
Antiy-AVLTrojan/Win32.VB.gic
KingsoftWin32.Malware.Heur_Generic.A.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmnot-a-virus:HEUR:AdWare.BAT.Shortcut.gen
GDataMemScan:Trojan.Clicker.Agent.ADQ
GoogleDetected
BitDefenderThetaGen:NN.ZexaF.34646.aiWfa0jX2E
ALYacMemScan:Trojan.Clicker.Agent.ADQ
MAXmalware (ai score=100)
VBA32BAT.TrojanClicker.Small.NAJ
MalwarebytesMalware.Heuristic.1001
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_CLICKER.RS
TencentWin32.Trojan.Agent.Hplw
YandexTrojan.CL.Agent!AOxQxk3/htY
SentinelOneStatic AI – Suspicious PE
FortinetW32/Agent.NAJ!tr
AVGBV:Click-B
AvastBV:Click-B
CrowdStrikewin/malicious_confidence_60% (W)

How to remove MemScan:Trojan.Clicker.Agent.ADQ?

MemScan:Trojan.Clicker.Agent.ADQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment