Trojan

Trojan-Downloader.Win32.Agent.cmqe removal guide

Malware Removal

The Trojan-Downloader.Win32.Agent.cmqe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Agent.cmqe virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan-Downloader.Win32.Agent.cmqe?


File Info:

name: CCA48F0C61555AAD8C7D.mlw
path: /opt/CAPEv2/storage/binaries/44d3152ef9d603f39d8066519e884456f60eee9c7e21541aec42e91bd5a21aac
crc32: E85BF19B
md5: cca48f0c61555aad8c7ddec958a9b83c
sha1: 22d609b8a952f561f021d0c2bfdf6d4745cd275a
sha256: 44d3152ef9d603f39d8066519e884456f60eee9c7e21541aec42e91bd5a21aac
sha512: c39e2bfb05c27c3647ed40c2f70c3747e7c3908937e28660829106c585aeb008e8289c73e24b275d70db46572a4eeb7207c0575a0cfff60d9fc87673a54a0273
ssdeep: 192:J+8EphNUtD/rFHYcIaaQ9vAbAA8kYp1aoKDCic8VKDqaKD7W3OA:VEpYNYXfM06kYpIoKDnnVKDqaKD7W3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T118627A09F6284849EDE08A3184A5AF77A118FC03D079AD6612FCBA5EED36E9FC705117
sha3_384: 8ca74698c3bc4f07bdebfb4d3103e692fd6abbdeaaf37ceb92091a8c0f684adcd7337e0ef7972e7cae258a3ac85078b2
ep_bytes: 60e80000000058059f0200008b3003f0
timestamp: 2009-08-11 01:53:03

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Microsoft
ProductName: Word Document
FileVersion: 1.00
ProductVersion: 1.00
InternalName: word
OriginalFilename: word.exe

Trojan-Downloader.Win32.Agent.cmqe also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lrNz
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.Downloader.am0@aCn!T6ji
FireEyeGeneric.mg.cca48f0c61555aad
SkyhighBehavesLike.Win32.Generic.lm
McAfeeArtemis!CCA48F0C6155
VIPREGen:Trojan.Downloader.am0@aCn!T6ji
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
BitDefenderGen:Trojan.Downloader.am0@aCn!T6ji
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.8a952f
BitDefenderThetaGen:NN.ZevbaF.36792.am0@aCn!T6ji
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
ClamAVWin.Trojan.Agent-713199
KasperskyTrojan-Downloader.Win32.Agent.cmqe
AlibabaTrojanDownloader:Win32/SScope.28949805
NANO-AntivirusTrojan.Win32.Agent.glfku
RisingDownloader.Agent!8.B23 (CLOUD)
SophosMal/Small-A
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.DownLoad3.6932
ZillyaDownloader.Agent.Win32.28791
TrendMicroTROJ_GEN.R002C0DK323
Trapminemalicious.moderate.ml.score
EmsisoftGen:Trojan.Downloader.am0@aCn!T6ji (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=97)
JiangminTrojanDownloader.Agent.bips
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/Downloader.LEPT-0493
Antiy-AVLTrojan[Downloader]/Win32.Agent
Kingsoftmalware.kb.b.982
MicrosoftTrojanDownloader:Win32/Small.gen!AP
XcitiumMalware@#1x5frmztek49
ArcabitTrojan.Downloader.ED119FC
ZoneAlarmTrojan-Downloader.Win32.Agent.cmqe
GDataGen:Trojan.Downloader.am0@aCn!T6ji
CynetMalicious (score: 100)
VBA32SScope.Trojan.VBRA.1579
ALYacGen:Trojan.Downloader.am0@aCn!T6ji
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DK323
TencentWin32.Trojan-Downloader.Agent.Ymhl
YandexTrojan.GenAsa!LN11V9fuVPE
IkarusTrojan-Downloader.Win32.Genome
MaxSecureTrojan.Malware.1471459.susgen
FortinetW32/Agent.CMQE!tr.dldr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Trojan-Downloader.Win32.Agent.cmqe?

Trojan-Downloader.Win32.Agent.cmqe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment