Spy Trojan

How to remove “Trojan-Spy.Win32.Agent.bqme”?

Malware Removal

The Trojan-Spy.Win32.Agent.bqme is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Agent.bqme virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Trojan-Spy.Win32.Agent.bqme?


File Info:

name: 428AD50B663BB3B37BA5.mlw
path: /opt/CAPEv2/storage/binaries/59c1103d45c92e6af14435391e3db11fb847f626c136906e9d7d8c71d45c0890
crc32: 21F3875B
md5: 428ad50b663bb3b37ba580a18cf174f6
sha1: e8626463477ed6e9734b987791e4a921f56fcce0
sha256: 59c1103d45c92e6af14435391e3db11fb847f626c136906e9d7d8c71d45c0890
sha512: 72fb0c0f2f2f0e24946c65d37b254420ab4e3fe6354509d174a1e85808a9ad4b08d21b850925432b0ae5f33a0f12953eb6e7c31856dfb3b34eba8da4b5bc777a
ssdeep: 6144:o6C5AXbMn7UI1FoV2gwTBlrIckPJYYYYYYYYYYYYx:o6RI1Fo/wT3cJYYYYYYYYYYYYx
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T162F4E68226C57099E0F3293A64B27267FF57AE707CF48517429E1E8CC763C53B8A1B91
sha3_384: 9ba7118e5eb22489d4eb9c2fb11710fa6ed20cc0a555d5ca9fe0acb5c5d0d41c0f7f6f588615f9f1ec804ba830fdbc28
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2011-03-17 08:58:08

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Uniscribe Unicode script processor
FileVersion: 1.0420.2600.5512 (xpsp.080413-2105)
InternalName: Uniscribe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: Uniscribe
ProductName: Microsoft(R) Uniscribe Unicode script processor
ProductVersion: 1.0420.2600.5512
Translation: 0x0409 0x04b0

Trojan-Spy.Win32.Agent.bqme also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Spy.20069
MicroWorld-eScanTrojan.GenericKD.38816663
FireEyeGeneric.mg.428ad50b663bb3b3
CAT-QuickHealTrojanPWS.Yunsip.A5
SkyhighBehavesLike.Win32.PWSYunsip.bz
McAfeePWS-Yunsip.gen.a
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKD.38816663
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 00060f0b1 )
K7AntiVirusTrojan ( 00060f0b1 )
BitDefenderThetaGen:NN.ZedlaF.36802.Tu@@a05rPXji
VirITTrojan.Win32.Agent.AMYE
SymantecW32.Yunsip
tehtrisGeneric.Malware
ESET-NOD32Win32/Spy.Agent.NYB
APEXMalicious
TrendMicro-HouseCallWORM_YUNSIP.SMR
ClamAVWin.Trojan.Yunsip-1
KasperskyTrojan-Spy.Win32.Agent.bqme
BitDefenderTrojan.GenericKD.38816663
NANO-AntivirusTrojan.Win32.Agent.vkmvm
SUPERAntiSpywareTrojan.Agent/Gen-Yunsip
AvastWin32:Yunsip-A [Wrm]
TencentTrojan.Win32.FakeMS.tpd
EmsisoftTrojan.GenericKD.38816663 (B)
F-SecureTrojan.TR/PSW.Yunsip.axyza
BaiduWin32.Trojan.Agent.amh
ZillyaTrojan.Agent.Win32.130937
TrendMicroWORM_YUNSIP.SMR
Trapminemalicious.moderate.ml.score
SophosMal/YunSip-A
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Generic.bhxd
GoogleDetected
AviraTR/PSW.Yunsip.axyza
VaristW32/Redosdru.B.gen!Eldorado
Antiy-AVLTrojan[PSW]/Win32.Yunsip.a
Kingsoftmalware.kb.a.996
MicrosoftPWS:Win32/Yunsip!pz
XcitiumTrojWare.Win32.TrojanSpy.Agent.ny@4pn6tf
ArcabitTrojan.Generic.D2504B97
ViRobotTrojan.Win32.Agent.131072.BJ
ZoneAlarmTrojan-Spy.Win32.Agent.bqme
GDataWin32.Trojan-Stealer.Yunsip.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Infostealer.R758
Acronissuspicious
VBA32TrojanSpy.Agent
ALYacTrojan.GenericKD.38816663
MAXmalware (ai score=81)
Cylanceunsafe
PandaGeneric Suspicious
RisingTrojan.Usp10Hijack!1.998B (CLASSIC)
YandexTrojan.GenAsa!LogooVIKaNc
IkarusTrojan.Spy.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.NYB!tr
AVGWin32:Yunsip-A [Wrm]
DeepInstinctMALICIOUS
alibabacloudPWS:Win/Yunsip.ed49dde8

How to remove Trojan-Spy.Win32.Agent.bqme?

Trojan-Spy.Win32.Agent.bqme removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment