Categories: Malware

About “Troj/Agent-AYQU” infection

The Troj/Agent-AYQU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Agent-AYQU virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the Kovter malware family

How to determine Troj/Agent-AYQU?


File Info:

name: 65BF0FE3E1B6017530F0.mlwpath: /opt/CAPEv2/storage/binaries/d4c076f49799c48ce9563d6e2c2b8ebc39fb6a5cecbb51f898015ca66a2ca4d4crc32: E4BD0658md5: 65bf0fe3e1b6017530f0fd8dd289c763sha1: 142fa1e5bfeade46b1c70186363f14b3b0a14317sha256: d4c076f49799c48ce9563d6e2c2b8ebc39fb6a5cecbb51f898015ca66a2ca4d4sha512: 639e84265aeea8162a3fcf32e46b9e0c4cd23503fe50fb378e7337aa0788af8e23fe19ee4c88bf6faf6208de164214dbebe112c13c87deda9701df9d6af75452ssdeep: 24576:BF6a06x/BYf2NAWddVXLHxeetTKHXy5QydTlNo:BTtxYcAWddVbHxtcMQyBlNtype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T146554A3AB681E237D42208BCCD0FE3D5A4A9F6302D359C57B7E41F4C54B6693AA1B643sha3_384: 025fb7683c1dc6acb56774ffd358afb62f1c9f73dc9b649dc63ebc12645d04d15587c048ec268f8234950348cae0287bep_bytes: ff8b55f88d45fce88490faff8b45fce8timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Troj/Agent-AYQU also known as:

Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Yakes.mDzK
AVG Sf:ShellCode-AO [Trj]
DrWeb Trojan.MulDrop7.63840
MicroWorld-eScan Gen:Variant.Graftor.938284
CAT-QuickHeal Trojan.Dynamer.S17445
McAfee GenericR-IPR!65BF0FE3E1B6
Malwarebytes Kovter.Trojan.Clicker.DDS
VIPRE Gen:Variant.Graftor.938284
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 00515bef1 )
Alibaba Trojan:Win32/PEMalform.fc8
K7GW Trojan ( 00515bef1 )
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZexaF.36196.rzZ@aCLzIbi
Cyren W32/Kovter.Z.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Kovter.I
Cynet Malicious (score: 100)
APEX Malicious
ClamAV Win.Packed.Alphaeon-9783095-0
BitDefender Gen:Variant.Graftor.938284
NANO-Antivirus Trojan.Win32.Kovter.ezpipb
Avast Sf:ShellCode-AO [Trj]
Tencent Trojan.Win32.Kovter.16000580
Emsisoft Gen:Variant.Graftor.938284 (B)
F-Secure Trojan.TR/Patched.Ren.Gen
Zillya Trojan.Kovter.Win32.4549
TrendMicro TROJ_GEN.R002C0PBP23
McAfee-GW-Edition BehavesLike.Win32.Generic.tt
Trapmine suspicious.low.ml.score
FireEye Generic.mg.65bf0fe3e1b60175
Sophos Troj/Agent-AYQU
SentinelOne Static AI – Malicious PE
GData Gen:Variant.Graftor.938284
Avira TR/Patched.Ren.Gen
MAX malware (ai score=86)
Antiy-AVL Trojan/Win32.TSGeneric
Xcitium TrojWare.Win32.Kovter.R@8f5pqh
Arcabit Trojan.Graftor.DE512C
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Trojan/Win32.Kovter.R197157
Acronis suspicious
ALYac Gen:Variant.Graftor.938284
TACHYON Trojan/W32.Agent.1339392.EY
Cylance unsafe
Panda Trj/Chgt.AD
TrendMicro-HouseCall TROJ_GEN.R002C0PBP23
Rising Trojan.Kovter!1.A7CF (CLASSIC)
Yandex Trojan.Kovter!5uE9ZC1IgDM
Ikarus Trojan.Win32.Kovter
MaxSecure Trojan.Malware.8522533.susgen
Fortinet W32/Kovter.I!tr
Cybereason malicious.3e1b60
DeepInstinct MALICIOUS

How to remove Troj/Agent-AYQU?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Graftor.636625 removal tips

The Graftor.636625 is considered dangerous by lots of security experts. When this infection is active,…

1 min ago

Troj/Luder-A information

The Troj/Luder-A is considered dangerous by lots of security experts. When this infection is active,…

37 mins ago

How to remove “Malware.AI.2017919460”?

The Malware.AI.2017919460 is considered dangerous by lots of security experts. When this infection is active,…

58 mins ago

Should I remove “Malware.AI.2861677099”?

The Malware.AI.2861677099 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Malware.AI.4183435755 information

The Malware.AI.4183435755 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Dropped:Application.Generic.3571726 removal instruction

The Dropped:Application.Generic.3571726 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago