Trojan

PowerShell/TrojanDownloader.Agent.Q removal guide

Malware Removal

The PowerShell/TrojanDownloader.Agent.Q is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PowerShell/TrojanDownloader.Agent.Q virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine PowerShell/TrojanDownloader.Agent.Q?


File Info:

crc32: C880532E
md5: b9343a27348fa90b36fc8957953acf77
name: B9343A27348FA90B36FC8957953ACF77.mlw
sha1: b8f2caae45f16cdecde101749d44522f951ab7c7
sha256: 238276b30a12ed0f0a7428be6c9cfe7d5368699103c806aec09fd471689e90ec
sha512: 3f61be37dacfd6c09b89c78bae53ce068c26ee2a1e5b423c1d3cde4aafcd9077f9cf9af78d7953cbf30944ce559b01e9f401ea2ae9738a841d246220be28442b
ssdeep: 768:CKeH2DH/rVfbzpY6kpeZgfYdYQzPmIGCXmAaNnPhlc8Zqg4YEFZqCyqxUcJ:Rv7/9WXklzPmI3m1P3rYgYzVy8UcJ
type: PE32+ executable (GUI) x86-64, for MS Windows

Version Info:

0: [No Data]

PowerShell/TrojanDownloader.Agent.Q also known as:

LionicTrojan.Win32.BitCoinMiner.4!c
Elasticmalicious (high confidence)
DrWebPowerShell.DownLoader.256
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.30857218
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.119985
SangforTrojan.Win32.Agent.8
CrowdStrikewin/malicious_confidence_80% (D)
Cybereasonmalicious.7348fa
CyrenW64/CoinMiner.V.gen!Eldorado
SymantecW97M.Downloader
ESET-NOD32PowerShell/TrojanDownloader.Agent.Q
APEXMalicious
AvastWin64:Malware-gen
ClamAVWin.Trojan.Coinminer-9837374-0
KasperskyTrojan.Win32.BitCoinMiner.ayo
BitDefenderTrojan.GenericKD.30857218
NANO-AntivirusTrojan.Win64.BitCoinMiner.fcgtml
MicroWorld-eScanTrojan.GenericKD.30857218
TencentWin32.Trojan.Bitcoinminer.Pezc
Ad-AwareTrojan.GenericKD.30857218
SophosMal/Generic-S
ComodoMalware@#1vc8wq9xf8786
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win64.Generic.pc
FireEyeGeneric.mg.b9343a27348fa90b
EmsisoftTrojan.GenericKD.30857218 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.BitCoinMiner.c
AviraHEUR/AGEN.1115805
Antiy-AVLTrojan/Generic.ASMalwS.262F8BD
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.30857218
AhnLab-V3Trojan/Win32.BitCoinMiner.C2126939
McAfeeArtemis!B9343A27348F
MAXmalware (ai score=96)
MalwarebytesMalware.AI.3618970343
PandaTrj/CI.A
YandexTrojan.GenAsa!pnOFf4yqwy0
IkarusPUA.CoinMiner
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/BitCoinMiner.AYO!tr
AVGWin64:Malware-gen
Paloaltogeneric.ml

How to remove PowerShell/TrojanDownloader.Agent.Q?

PowerShell/TrojanDownloader.Agent.Q removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment