Malware

About “Troj/Agent-AYQU” infection

Malware Removal

The Troj/Agent-AYQU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Agent-AYQU virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the Kovter malware family

How to determine Troj/Agent-AYQU?


File Info:

name: 65BF0FE3E1B6017530F0.mlw
path: /opt/CAPEv2/storage/binaries/d4c076f49799c48ce9563d6e2c2b8ebc39fb6a5cecbb51f898015ca66a2ca4d4
crc32: E4BD0658
md5: 65bf0fe3e1b6017530f0fd8dd289c763
sha1: 142fa1e5bfeade46b1c70186363f14b3b0a14317
sha256: d4c076f49799c48ce9563d6e2c2b8ebc39fb6a5cecbb51f898015ca66a2ca4d4
sha512: 639e84265aeea8162a3fcf32e46b9e0c4cd23503fe50fb378e7337aa0788af8e23fe19ee4c88bf6faf6208de164214dbebe112c13c87deda9701df9d6af75452
ssdeep: 24576:BF6a06x/BYf2NAWddVXLHxeetTKHXy5QydTlNo:BTtxYcAWddVbHxtcMQyBlN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T146554A3AB681E237D42208BCCD0FE3D5A4A9F6302D359C57B7E41F4C54B6693AA1B643
sha3_384: 025fb7683c1dc6acb56774ffd358afb62f1c9f73dc9b649dc63ebc12645d04d15587c048ec268f8234950348cae0287b
ep_bytes: ff8b55f88d45fce88490faff8b45fce8
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Troj/Agent-AYQU also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Yakes.mDzK
AVGSf:ShellCode-AO [Trj]
DrWebTrojan.MulDrop7.63840
MicroWorld-eScanGen:Variant.Graftor.938284
CAT-QuickHealTrojan.Dynamer.S17445
McAfeeGenericR-IPR!65BF0FE3E1B6
MalwarebytesKovter.Trojan.Clicker.DDS
VIPREGen:Variant.Graftor.938284
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00515bef1 )
AlibabaTrojan:Win32/PEMalform.fc8
K7GWTrojan ( 00515bef1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36196.rzZ@aCLzIbi
CyrenW32/Kovter.Z.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kovter.I
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Alphaeon-9783095-0
BitDefenderGen:Variant.Graftor.938284
NANO-AntivirusTrojan.Win32.Kovter.ezpipb
AvastSf:ShellCode-AO [Trj]
TencentTrojan.Win32.Kovter.16000580
EmsisoftGen:Variant.Graftor.938284 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
ZillyaTrojan.Kovter.Win32.4549
TrendMicroTROJ_GEN.R002C0PBP23
McAfee-GW-EditionBehavesLike.Win32.Generic.tt
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.65bf0fe3e1b60175
SophosTroj/Agent-AYQU
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Graftor.938284
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.TSGeneric
XcitiumTrojWare.Win32.Kovter.R@8f5pqh
ArcabitTrojan.Graftor.DE512C
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Kovter.R197157
Acronissuspicious
ALYacGen:Variant.Graftor.938284
TACHYONTrojan/W32.Agent.1339392.EY
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0PBP23
RisingTrojan.Kovter!1.A7CF (CLASSIC)
YandexTrojan.Kovter!5uE9ZC1IgDM
IkarusTrojan.Win32.Kovter
MaxSecureTrojan.Malware.8522533.susgen
FortinetW32/Kovter.I!tr
Cybereasonmalicious.3e1b60
DeepInstinctMALICIOUS

How to remove Troj/Agent-AYQU?

Troj/Agent-AYQU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment