Ransom Trojan

Trojan-Ransom.MSIL.Agent.fqkh removal instruction

Malware Removal

The Trojan-Ransom.MSIL.Agent.fqkh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.MSIL.Agent.fqkh virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan-Ransom.MSIL.Agent.fqkh?


File Info:

crc32: 506E2178
md5: dbef0ff24550b2004cabab189ddfc66f
name: DBEF0FF24550B2004CABAB189DDFC66F.mlw
sha1: 2040c3248717859136469557185ceb09ae79a52b
sha256: 32e33608d05d650e4fc4b6c499c4c72de701cfb576461e9f1e779ac6e467641c
sha512: 4672edcd95c9b65b2c5a425d236e2334a577562813ad7362d3b999caf34b2f6e0ae2c9b2bd78cab7377339ba0238658872334a72afdd02896c4c1cb78762a671
ssdeep: 6144:vVbjzQDSNvBcS0XflSLgiJWS/YmeuFP5aTQAkHuQuTgcfjarHHswmLrbu2gyaqm:hz4TSSflI/YmpK0pdWgKRa2gyaqmEE
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: Exocrypt.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Exocrypt
ProductVersion: 1.0.0.0
FileDescription: Exocrypt
OriginalFilename: Exocrypt.exe

Trojan-Ransom.MSIL.Agent.fqkh also known as:

K7AntiVirusTrojan ( 0052e40a1 )
LionicTrojan.Win32.Generic.4!c
ALYacTrojan.Ransom.Exocrypt
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0052e40a1 )
Cybereasonmalicious.24550b
ESET-NOD32a variant of MSIL/Filecoder.MZ
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyTrojan-Ransom.MSIL.Agent.fqkh
BitDefenderGen:Heur.Ransom.HiddenTears.1
NANO-AntivirusTrojan.Win32.Ransom.fajjcp
MicroWorld-eScanGen:Heur.Ransom.HiddenTears.1
TencentWin32.Trojan.Ransom.Wvut
Ad-AwareGen:Heur.Ransom.HiddenTears.1
SophosMal/Generic-S + Mal/Ramsil-X
BitDefenderThetaGen:NN.ZemsilF.34126.Dm0@a0BKdWh
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_EXOCRYPT.THDBDAH
McAfee-GW-EditionRansom-Exocrypt!DBEF0FF24550
FireEyeGen:Heur.Ransom.HiddenTears.1
EmsisoftGen:Heur.Ransom.HiddenTears.1 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1137893
MicrosoftBackdoor:Win32/Bladabindi!ml
ZoneAlarmTrojan-Ransom.MSIL.Agent.fqkh
GDataGen:Heur.Ransom.HiddenTears.1
AhnLab-V3Trojan/Win32.MSIL.C2472168
McAfeeRansom-Exocrypt!DBEF0FF24550
MalwarebytesMalware.AI.1020336861
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_EXOCRYPT.THDBDAH
YandexTrojan.Filecoder!leuFk7r/42w
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Filecoder.MZ!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan-Ransom.MSIL.Agent.fqkh?

Trojan-Ransom.MSIL.Agent.fqkh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment