Trojan

MSIL/TrojanDownloader.Agent.LQB malicious file

Malware Removal

The MSIL/TrojanDownloader.Agent.LQB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/TrojanDownloader.Agent.LQB virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/TrojanDownloader.Agent.LQB?


File Info:

name: 5A62DED4F193338CEF98.mlw
path: /opt/CAPEv2/storage/binaries/bee733853d68be682439b040c892b2bfcc1d7647fe9bde5d1a2f3a19887a6d31
crc32: E37E668B
md5: 5a62ded4f193338cef98cee26a907570
sha1: ec0c2e239ff2782e51d9f10fe6edb60cd15a6719
sha256: bee733853d68be682439b040c892b2bfcc1d7647fe9bde5d1a2f3a19887a6d31
sha512: 9b8266ba98848683945e8ad53061304e3157c16dc7a484a978b1b3509a0d309e2f943192048b3f1cd22b58f65396abeeffa96b6b9a42dc54b0f0397043f43da1
ssdeep: 768:+pK8Gdkb+2L6hJoHNzfgQy6Ju9VIls0zrKmp41s8Gbt8h:8QyB6hJoHNzFXJGIlsgrKmp4aPhy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T125236A439B6C1374C6964D3A9921288887F3DD69660EFE985DC4B0038F7BBDABD035D1
sha3_384: 17619bf236cb7a75e48b6d0aa2c4673a16a52f09ce4cf5471c3a920e8c4f38bb6c06f74d22ac1df4a1734fb59ca403d1
ep_bytes: ff250020400000000000000000000000
timestamp: 2074-11-06 04:26:45

Version Info:

Translation: 0x0000 0x04b0
Comments: WhatsApp
CompanyName: WhatsApp
FileDescription: WhatsApp
FileVersion: 2.2210.9.0
InternalName: Dowcb.exe
LegalCopyright: Copyright © 2022 WhatsApp
LegalTrademarks:
OriginalFilename: Dowcb.exe
ProductName: WhatsApp
ProductVersion: 2.2210.9.0
Assembly Version: 2.2210.9.0

MSIL/TrojanDownloader.Agent.LQB also known as:

BkavW32.AIDetectNet.01
MicroWorld-eScanTrojan.GenericKD.39580854
FireEyeTrojan.GenericKD.39580854
ALYacTrojan.GenericKD.39580854
CylanceUnsafe
SangforTrojan.MSIL.Stealer.gen
BitDefenderThetaGen:NN.ZemsilCO.34638.dm0@aCNsu1h
VirITTrojan.Win32.PSWStealer.DHS
CyrenW32/MSIL_Kryptik.HDO.gen!Eldorado
SymantecMSIL.Downloader!gen7
Elasticmalicious (moderate confidence)
ESET-NOD32MSIL/TrojanDownloader.Agent.LQB
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.MSIL.Stealer.gen
BitDefenderTrojan.GenericKD.39580854
AvastWin32:DropperX-gen [Drp]
TencentMsil.Trojan-downloader.Agent.Swus
Ad-AwareTrojan.GenericKD.39580854
EmsisoftTrojan.GenericKD.39580854 (B)
DrWebTrojan.Siggen17.47508
McAfee-GW-EditionBehavesLike.Win32.Trojan.ph
SentinelOneStatic AI – Suspicious PE
SophosMal/Generic-S + Troj/MSILIn-BAC
APEXMalicious
GDataTrojan.GenericKD.39580854
ArcabitTrojan.Generic.D25BF4B6
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Dropper/Win.Generic.C5106174
McAfeeRDN/Generic.grp
MAXmalware (ai score=83)
IkarusWin32.SuspectCrc
FortinetMSIL/Agent.LQB!tr.dldr
AVGWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove MSIL/TrojanDownloader.Agent.LQB?

MSIL/TrojanDownloader.Agent.LQB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment