Trojan

Trojan.Agent.EXQA (file analysis)

Malware Removal

The Trojan.Agent.EXQA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.EXQA virus can do?

  • The office file contains anomalous features
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs
  • Martian Subprocess Started By Office Process

How to determine Trojan.Agent.EXQA?


File Info:

crc32: 8FAE35C0
md5: 8ad36671486f69dfdc4964a5ceaeb9d6
name: upload_file
sha1: 08bca761f604886b8215f418dd42e879e7a2adf4
sha256: 72e4eb98d0bff0e9f4788d5044c3339b2d109fd1c417b3f00df0a79ae413b427
sha512: ae10067908eda17cf6e7e233ad57676a729ca7e1a3f8cb99024ea1aa7a53f47306607576336c1a24e9a1b4fe2dc235ef5ea7e611ef07f75d7a4a3617bc55f88a
ssdeep: 768:cmQk3hOdsylKlgxopeiBNhZFGzE+cL2kdAJ29pzNWYBsf9tmMIwyYeCAuv:yk3hOdsylKlgxopeiBNhZFGzE+cL2kdG
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Author: cbURl, Last Saved By: Administrator, Name of Creating Application: Microsoft Excel, Create Time/Date: Fri Jun 5 19:17:20 2015, Last Saved Time/Date: Wed Oct 14 11:04:18 2020, Security: 0

Version Info:

0: [No Data]

Trojan.Agent.EXQA also known as:

MicroWorld-eScanTrojan.Agent.EXQA
FireEyeTrojan.Agent.EXQA
CAT-QuickHealOle.Trojan.A1025938
AegisLabTrojan.MSOffice.Generic.4!c
K7AntiVirusTrojan ( 00568efb1 )
K7GWTrojan ( 00568efb1 )
CyrenXF/Sneaky.BL.gen!Camelot
SymantecTrojan.Gen.2
ESET-NOD32DOC/Kryptik.AE
KasperskyHEUR:Trojan.Script.Generic
BitDefenderTrojan.Agent.EXQA
Ad-AwareTrojan.Agent.EXQA
EmsisoftTrojan.Agent.EXQA (B)
F-SecureMalware.W97M/Kryptik.lcktm
McAfee-GW-EditionArtemis!Trojan
IkarusTrojan.DOC.Crypt
AviraW97M/Kryptik.lcktm
MicrosoftTrojanDownloader:O97M/EncDoc.YS!MTB
ArcabitTrojan.Agent.EXQA
AhnLab-V3Trojan/BIN.Maldoc
ZoneAlarmHEUR:Trojan.Script.Generic
GDataTrojan.Agent.EXQA
CynetMalicious (score: 85)
ALYacTrojan.Agent.EXQA
ZonerProbably Heur.W97ShellB
FortinetMSExcel/Kryptik.AE!tr.dldr
Qihoo-360Generic/Trojan.68f

How to remove Trojan.Agent.EXQA?

Trojan.Agent.EXQA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment