Trojan

What is “Trojan.Agent.DQRB”?

Malware Removal

The Trojan.Agent.DQRB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.DQRB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Agent.DQRB?


File Info:

name: B51A44935F57B4B4ABD6.mlw
path: /opt/CAPEv2/storage/binaries/ff0dbd471f72845cb57a7b47904acb210e26204dc4267385d358dfd1d3652133
crc32: ADEB5ABA
md5: b51a44935f57b4b4abd69382fa322343
sha1: 5760263fdb4b4deabae863ccac1abab5c002f996
sha256: ff0dbd471f72845cb57a7b47904acb210e26204dc4267385d358dfd1d3652133
sha512: 7064056f1f1ddce2f99cf2d208686dbb38bedafdca9a282cf737848f962e0d99f08a6abe70c6df7469ad3fafbf93c6fc700bf0763336316b01f5cca10b3d1595
ssdeep: 768:R/LkRDP4t/ioKLiLGOYqmsSXeHF9AjZc9hTlCfkiiFF8ZwNHRo2UY7ay7rJBvhDN:m0KoK+LGndsSXcZhTIpiF8Monm79D0S
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A9538D13B8D1C573C08246B51DA2CB56AF3BB1210A3AC117BBAC9A5F1F74590D52E39F
sha3_384: 2e5ef2d8562108d70bc25b86f7cb2adcb0289f59cd079e931b1fb2660c2367bc595de155c500809f5f4e06652c60c5c1
ep_bytes: 00000000000000000000000000000000
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan.Agent.DQRB also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Sixer.tng9
CynetMalicious (score: 100)
FireEyeGeneric.mg.b51a44935f57b4b4
McAfeeGenericRXAA-FA!B51A44935F57
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.4014526
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 7000000f1 )
AlibabaTrojan:Win32/Kryptik.e8199de2
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.35f57b
CyrenW32/Picsys.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Kryptik.GYLL
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Proxy-3993
KasperskyUDS:Trojan-Proxy.Win32.Agent.ylv
BitDefenderTrojan.Agent.DQRB
MicroWorld-eScanTrojan.Agent.DQRB
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan.Crypt.Cgow
SophosMal/Generic-S
BaiduWin32.Worm.Picsys.a
F-SecureTrojan.TR/Crypt.ULPM.Gen
DrWebTrojan.Proxy.24148
VIPRETrojan.Agent.DQRB
TrendMicroTROJ_GEN.R002C0WAU23
McAfee-GW-EditionBehavesLike.Win32.Generic.km
Trapminemalicious.high.ml.score
EmsisoftTrojan.Agent.DQRB (B)
Ikarusnot-a-virus:Server-Proxy.Win32.Sock4Proxy
GDataWin32.Trojan.PSE.11PHGCR
JiangminTrojanProxy.Agent.ecp
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.SGeneric
ArcabitTrojan.Agent.DQRB
ZoneAlarmUDS:Trojan-Proxy.Win32.Agent.ylv
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R258250
VBA32TrojanProxy.Agent
MalwarebytesGeneric.Trojan.Delf.DDS
TrendMicro-HouseCallTROJ_GEN.R002C0WAU23
RisingTrojan.Generic@AI.96 (RDMK:A0SlEssnRqksyaubgdUJ0w)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/ULPM.16C0!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/Chgt.AC
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Trojan.Agent.DQRB?

Trojan.Agent.DQRB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment