Trojan

Trojan.Agent.BHQZ removal tips

Malware Removal

The Trojan.Agent.BHQZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BHQZ virus can do?

  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Agent.BHQZ?


File Info:

name: 8ACAFA96C3AC4D22EE0B.mlw
path: /opt/CAPEv2/storage/binaries/00c2b220f3c1c882bfbb69ae0ed85861d78b2920c1954a0f6daaaadc49598d74
crc32: C152F306
md5: 8acafa96c3ac4d22ee0b62384d0f4054
sha1: 184728b4e9e342a912e180076fc7e7084486f13d
sha256: 00c2b220f3c1c882bfbb69ae0ed85861d78b2920c1954a0f6daaaadc49598d74
sha512: c9c792f165d55f0d6a05d4812af88c2084758b26896b0072e2f3726893775e9cec48c1045b2a444319b850dbd70a0d2c0b90c52f144d4dfd9890474e61e06139
ssdeep: 12288:bMJtKxT00kIRtUIfDinNM4uf6Nx6eJ7JauTQQK84vEdmPkm0qD/iIonehO5hf:oJAt0aUIfOnNw676oJd0y4vEdmPkmwr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13FF49E32F6918433D2731A349C1BA3D99939BF512E68AC477BF82D4C5F7968138292D3
sha3_384: b7cfdc2f7ab3c3826922abc9e68b6de05e386ca14acc925f6ede3678da6347118b71fe733119b98733b1abc3787dc2a8
ep_bytes: 4d5a50000200000004000f00ffff0000
timestamp: 2013-08-04 18:31:54

Version Info:

0: [No Data]

Trojan.Agent.BHQZ also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.Agent.BHQZ
FireEyeGeneric.mg.8acafa96c3ac4d22
McAfeeArtemis!8ACAFA96C3AC
CylanceUnsafe
VIPRETrojan.Agent.BHQZ
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 004b57461 )
K7GWSpyware ( 004b57461 )
Cybereasonmalicious.6c3ac4
VirITTrojan.Win32.Banker6.CAUU
CyrenW32/Banker.BM.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Banker.ZZW
APEXMalicious
ClamAVWin.Trojan.Agent-1256158
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.Agent.BHQZ
NANO-AntivirusTrojan.Win32.Banker.fbhxte
AvastWin32:Banker-KLO [Trj]
TencentWin32.Trojan.Crypt.Edxy
Ad-AwareTrojan.Agent.BHQZ
EmsisoftTrojan.Agent.BHQZ (B)
ComodoTrojWare.Win32.Spy.Banker.IK@5s7cfv
McAfee-GW-EditionBehavesLike.Win32.Infected.bh
Trapminemalicious.high.ml.score
SophosMal/Generic-S (PUA)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Agent.BHQZ
AviraTR/Crypt.XPACK.Gen3
Antiy-AVLTrojan/Generic.ASMalwFH.3C54
KingsoftWin32.Troj.Agent.v.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
ALYacTrojan.Agent.BHQZ
MAXmalware (ai score=80)
MalwarebytesMalware.Heuristic.1001
RisingTrojan.Injector!1.DF63 (CLASSIC)
IkarusTrojan-PWS.Banker6
FortinetW32/Banker.ZZW!tr.spy
BitDefenderThetaGen:NN.ZelphiF.34582.UOW@aWrjiSjO
AVGWin32:Banker-KLO [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan.Agent.BHQZ?

Trojan.Agent.BHQZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment