Trojan

Trojan.AgentWDCR.QHX removal guide

Malware Removal

The Trojan.AgentWDCR.QHX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AgentWDCR.QHX virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Unconventionial language used in binary resources: Macedonian
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs

How to determine Trojan.AgentWDCR.QHX?


File Info:

crc32: AF414B4E
md5: 78d164f8cc8430d730e849876d4e51e3
name: 78D164F8CC8430D730E849876D4E51E3.mlw
sha1: b15747047d192a178e3ab89baff8c7b48250b9fd
sha256: 2c84fa00fd49cb5162b18f20cf0aecbe2a93a38bd6111354fc9c32865ef94d14
sha512: 7cf19d3626237718de05884d96befd5da79afde2d3f7687b1c4a515771cd119220a56f02f7b9be4c2fac432b32f77fd2bc092ee7a9999a42b022643517d751da
ssdeep: 6144:SIR2b+Wob95vyQq9BYJFb1ZNZ7r5Ru2gYgmwGOV:ZWozvt3Fb1ZN7RdRgmwGO
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017, ticel
FileVersion: 9.8.8.46
ProductVersion: 9.8.8.46

Trojan.AgentWDCR.QHX also known as:

K7AntiVirusTrojan ( 0001140e1 )
LionicTrojan.Win32.Agentb.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.41480
CynetMalicious (score: 100)
CAT-QuickHealTrojan.MauvaiseRI.S5264681
ALYacTrojan.Agent.Diple
CylanceUnsafe
ZillyaTrojan.Diple.Win32.98512
SangforTrojan.Win32.Occamy.B
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Occamy.6cecb4e8
K7GWTrojan ( 0001140e1 )
Cybereasonmalicious.8cc843
CyrenW32/Injector.LDMO-6829
SymantecTrojan Horse
ESET-NOD32MSIL/Flooder.Agent.DM
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Agentb.jiub
BitDefenderTrojan.AgentWDCR.QHX
NANO-AntivirusTrojan.Win32.Packed2.flueym
ViRobotTrojan.Win32.S.Agent.235008.HX
MicroWorld-eScanTrojan.AgentWDCR.QHX
TencentMalware.Win32.Gencirc.114d6099
Ad-AwareTrojan.AgentWDCR.QHX
SophosMal/Generic-R + Troj/Ransom-FEF
ComodoMalware@#138x1gns39ewa
BitDefenderThetaGen:NN.ZemsilF.34294.om0@aeHSLWoO
VIPREWin32.Malware!Drop
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.78d164f8cc8430d7
EmsisoftTrojan.AgentWDCR.QHX (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agentb.ehp
WebrootW32.Malware.Gen
AviraTR/AD.MalwareCrypter.dtrpv
Antiy-AVLTrojan/Generic.ASMalwS.2A11002
MicrosoftTrojan:Win32/Occamy.B!bit
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
GDataWin32.Trojan.Agent.2CRB3C
AhnLab-V3Trojan/Win32.Diple.C2913671
Acronissuspicious
McAfeeGeneric.buk
VBA32Trojan.MSIL.Diple
PandaTrj/WLT.E
YandexTrojan.Agentb!thjxgSMCcsM
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Malware.73715893.susgen
FortinetMSIL/Injector.UEL!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.AgentWDCR.QHX?

Trojan.AgentWDCR.QHX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment