Trojan

How to remove “MSIL/TrojanDownloader.Agent.GWQ”?

Malware Removal

The MSIL/TrojanDownloader.Agent.GWQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.GWQ virus can do?

  • Presents an Authenticode digital signature
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/TrojanDownloader.Agent.GWQ?


File Info:

crc32: 6E45B765
md5: 4f7f2aec51d6f089ff11faa851109608
name: upload_file
sha1: 57c7fa9f578b30a8ddaad8e2cfceccd28c69bfff
sha256: 4fedda898f576336ee03b6171f90a06d6132b314d37e4ff58e1b0a5b1fdc05dc
sha512: 458f7edbe8c997091803e032439eaf3658fbfe37d8711d909ef8f1aae5b7035b1fbd3bef69376f900845672a20142dc067dc97ffa4688c1dcd65da49f74ecab7
ssdeep: 3072:3wmV+j+25XzMaAmO1rgbG9X8vzj4URDbuHeCoUr1pvSEN+VeWoDO5wNhoQOQeCFn:AmVNSzMMO1gNCz/1NeSDOydFB
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa9 x52d2x4e1dx4e1d. All rights reserved.
Assembly Version: 8.6.0.0
FileVersion: 0.4.6.6
CompanyName: x827ex4e1dx5f17
LegalTrademarks: x426x5f17x52d2
Comments: x5f17x5f17x4e1d x4e1dx426x426
ProductName: x4e1dx426x5f17 x827ex426x52d2
ProductVersion: 8.6.0.0
FileDescription: x5f17x426x52d2 x426x426x827e
OriginalFilename: x4e1dx426x5f17 x827ex426x52d2.exe
Translation: 0x0409 0x0514

MSIL/TrojanDownloader.Agent.GWQ also known as:

Elasticmalicious (high confidence)
FireEyeGeneric.mg.4f7f2aec51d6f089
McAfeeArtemis!4F7F2AEC51D6
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.f578b3
SymantecTrojan.Gen.2
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
IkarusTrojan.MSIL.Inject
MicrosoftTrojan:Win32/Woreflint.A!cl
ZoneAlarmUDS:DangerousObject.Multi.Generic
BitDefenderThetaGen:NN.ZemsilF.34566.sm1@aa!bF4li
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.GWQ
FortinetMalicious_Behavior.SB
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml

How to remove MSIL/TrojanDownloader.Agent.GWQ?

MSIL/TrojanDownloader.Agent.GWQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment