Ransom Trojan

What is “Trojan-Ransom.Win32.Agent.azwq”?

Malware Removal

The Trojan-Ransom.Win32.Agent.azwq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Agent.azwq virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Ransom.Win32.Agent.azwq?


File Info:

crc32: CC549075
md5: bed0c3259456ddca403cd6859492577e
name: BED0C3259456DDCA403CD6859492577E.mlw
sha1: 62e89ed3efcf9fc64566a12ddcd3a33e6056d3e9
sha256: 4dbcb8a8cd047eb241f3fcea2091b064fc0bd66d4c206aa573312854efa053fd
sha512: 73f920ab97235aebb9266e7e325f1a99da3386a64de9746a9f0cf0fb71d4b4e50436efb8dff297377258449b0e99bf769c4d7ea1f0f6baa30b556bdbfd2f24d2
ssdeep: 3072:jvNjeIlwPZG4C6YQb/PxmiUIhlTLXn6v8:jvNjAgQ7pmVILX6
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2003 - 2011 Nir Sofer
InternalName: NirCmd
FileVersion: 2.65
CompanyName: NirSoft
ProductName: NirCmd
ProductVersion: 2.65
FileDescription: NirCmd
OriginalFilename: NirCmd.exe
Translation: 0x0409 0x04b0

Trojan-Ransom.Win32.Agent.azwq also known as:

K7AntiVirusTrojan ( 004f8bc31 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.5047
CynetMalicious (score: 100)
CAT-QuickHealRansom.Crowti.MUE.A6
ALYacGen:Variant.Ransom.CryptXXX.1
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1304144
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004f8bc31 )
Cybereasonmalicious.59456d
CyrenW32/Ransom.CJ.gen!Eldorado
SymantecRansom.CryptXXX!g17
ESET-NOD32a variant of Win32/Kryptik.HGEN
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.Agent.azwq
BitDefenderGen:Variant.Ransom.CryptXXX.1
NANO-AntivirusTrojan.Win32.Kryptik.evqhwj
MicroWorld-eScanGen:Variant.Ransom.CryptXXX.1
TencentMalware.Win32.Gencirc.10b58c19
Ad-AwareGen:Variant.Ransom.CryptXXX.1
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34686.gy0@auDrEImU
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroRansom_HPCRYPMIC.SM4
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
FireEyeGeneric.mg.bed0c3259456ddca
EmsisoftGen:Variant.Ransom.CryptXXX.1 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1128192
eGambitUnsafe.AI_Score_95%
MicrosoftTrojan:Win32/Ditertag.A
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmTrojan-Ransom.Win32.Agent.azwq
GDataGen:Variant.Ransom.CryptXXX.1
AhnLab-V3Malware/Win32.RL_Generic.R285865
Acronissuspicious
McAfeeRansomware-FTK!BED0C3259456
MAXmalware (ai score=99)
VBA32BScope.Trojan.Bagsu
MalwarebytesTrojan.Crypt
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPCRYPMIC.SM4
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazpAlJIlqx7rxJsUHKF/SIH8)
IkarusTrojan-Ransom.Tovicrypt
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Trojan-gen

How to remove Trojan-Ransom.Win32.Agent.azwq?

Trojan-Ransom.Win32.Agent.azwq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment