Trojan

About “Trojan-Downloader.Win32.Agent.gxwq” infection

Malware Removal

The Trojan-Downloader.Win32.Agent.gxwq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Agent.gxwq virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan-Downloader.Win32.Agent.gxwq?


File Info:

name: B957682B8914B947001D.mlw
path: /opt/CAPEv2/storage/binaries/6605e50ae57923074ffbb422a1ad24b1d5d8169565c57e1d7f8e15f68e7e0b39
crc32: 19C9371D
md5: b957682b8914b947001df0c0e8ffcc3f
sha1: 720a3d8d969a98073f956d4ed0aff3084ed09347
sha256: 6605e50ae57923074ffbb422a1ad24b1d5d8169565c57e1d7f8e15f68e7e0b39
sha512: e5a62817a546dcd51a00d01ec68e5fb527e7b2737c2cb2b54aca6bc5a3b370edaa96e09ce2c2cbfd799ba6586a342487a94a24d7b66d925317052f419d0c0774
ssdeep: 384:K9qLXopi1z2MQLa9eWTodJppVgkWUK3a8q8:K9qLXopi1z7uOWdJppPWc8q8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T166B23A4894A40471E3E0C730553A9E39812B9FED96B9DA0F0F50FCA93FBF392586241E
sha3_384: 0546e3a0ad07c8ab4397f860ed7ead8a19ba60a645325f5c578d08b2501fb62cefd3b06922d12f3ebe14b0a4b0ba6938
ep_bytes: 558bec6aff68c8364000689e24400064
timestamp: 2011-09-13 11:05:31

Version Info:

Comments:
CompanyName: Shenzhen QVOD Technology Co.,Ltd
FileDescription: QvodInstall Module
FileVersion: 3, 0, 0, 0
InternalName: QvodInstall.exe
LegalCopyright: Copyright(C) 2006-2009 QVOD
LegalTrademarks:
OriginalFilename: QvodInstall.exe
PrivateBuild:
ProductName: QvodInstall Module
ProductVersion: 3, 0, 0, 0
SpecialBuild:
Translation: 0x0804 0x04b0

Trojan-Downloader.Win32.Agent.gxwq also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.91710
FireEyeGeneric.mg.b957682b8914b947
McAfeeGenericRXAA-AA!B957682B8914
CylanceUnsafe
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.d969a9
BitDefenderThetaGen:NN.ZexaF.34646.bi0@auI8DVhb
SymantecML.Attribute.HighConfidence
BaiduWin32.Trojan-Dropper.Agent.s
AvastWin32:Trojan-gen
KasperskyTrojan-Downloader.Win32.Agent.gxwq
BitDefenderTrojan.GenericKDZ.91710
NANO-AntivirusTrojan.Win32.Agent.bddwuk
CynetMalicious (score: 100)
Ad-AwareTrojan.GenericKDZ.91710
EmsisoftTrojan.GenericKDZ.91710 (B)
ComodoTrojWare.Win32.Downloader.Agent.gxwq@4oscoe
DrWebTrojan.DownLoad2.38717
VIPRETrojan.GenericKDZ.91710
SentinelOneStatic AI – Malicious PE
SophosMal/Generic-S
APEXMalicious
GDataTrojan.GenericKDZ.91710
JiangminTrojanDownloader.Agent.drfh
AviraTR/Patched.Ren.Gen
Antiy-AVLTrojan/Generic.ASMalwS.13
ViRobotTrojan.Win32.A.Downloader.40960.AK
ZoneAlarmTrojan-Downloader.Win32.Agent.gxwq
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Swisyn.R14071
MAXmalware (ai score=87)
MalwarebytesNimnul.Virus.FileInfector.DDS
RisingTrojan.Win32.AVplayer.z (CLASSIC)
IkarusVirus.Win32.Jadtre
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan-Downloader.Win32.Agent.gxwq?

Trojan-Downloader.Win32.Agent.gxwq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment