Spy Trojan

Should I remove “Trojan-Spy.Win32.Agent.jqvo”?

Malware Removal

The Trojan-Spy.Win32.Agent.jqvo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Agent.jqvo virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • A named pipe was used for inter-process communication
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • A script process created a new process
  • Harvests cookies for information gathering
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-Spy.Win32.Agent.jqvo?


File Info:

name: 72828E7DCEF0A5433813.mlw
path: /opt/CAPEv2/storage/binaries/012b19ddb5b8e623c2d59e3c65679aa14a66d2a32cb1c812ea9bed548dfebb62
crc32: 15E39DA2
md5: 72828e7dcef0a5433813eb89c2194726
sha1: 773d0cb18700b891224c609760dd0942f90564df
sha256: 012b19ddb5b8e623c2d59e3c65679aa14a66d2a32cb1c812ea9bed548dfebb62
sha512: 88bfa917b08228e068f27e01bcdbc0db95e404bd77daf6afdb8557d995605cadea6f796472712dfb73b2b5b58bcfde224031bc30a00185930241292080f35850
ssdeep: 98304:BWgmaEIwAxkN0tR38/RkO6srhTcyI9CSd9s+B54:ggm3IPfd8/eRecyI95d9sO4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1530633124DA2F469C374597E3A32F22F9A2CF4EDA357727F2196B50B9009B90F9C4271
sha3_384: 724014a3e36156f9dcef7e1edc22da52c07b0dcd9de6fa141057a2383de134837e736dc6986a7f57c99eba6b948ae015
ep_bytes: 60be00e043008dbe0030fcff5783cdff
timestamp: 2016-08-14 19:15:49

Version Info:

0: [No Data]

Trojan-Spy.Win32.Agent.jqvo also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKD.40455154
FireEyeGeneric.mg.72828e7dcef0a543
ALYacTrojan.GenericKD.40455154
CylanceUnsafe
VIPRETrojan.GenericKD.40455154
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0053c6091 )
BitDefenderTrojan.GenericKD.40455154
K7GWTrojan ( 0053c6091 )
Cybereasonmalicious.dcef0a
ArcabitTrojan.Generic.D2694BF2
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
TrendMicro-HouseCallTrojan.Win32.ADWIND.CSX
Paloaltogeneric.ml
ClamAVWin.Malware.Filerepmalware-9810618-0
KasperskyTrojan-Spy.Win32.Agent.jqvo
NANO-AntivirusTrojan.Win32.CommandCam.fjghkg
TencentWin32.Trojan-spy.Agent.Agkw
Ad-AwareTrojan.GenericKD.40455154
EmsisoftTrojan.GenericKD.40455154 (B)
ComodoMalware@#3dlz7nylj7sek
F-SecureHeuristic.HEUR/AGEN.1215238
DrWebTrojan.MulDrop8.37154
ZillyaTrojan.Tepfer.Win32.83753
TrendMicroTrojan.Win32.ADWIND.CSX
McAfee-GW-EditionBehavesLike.Win32.Trojan.wc
Trapminemalicious.moderate.ml.score
SophosGeneric PUA HH (PUA)
APEXMalicious
JiangminClient-SMTP.Blat.au
Antiy-AVLTrojan/Generic.ASMalwS.18F1
KingsoftWin32.Troj.Generic.lc.(kcloud)
MicrosoftTrojan:Win32/Occamy.C01
GDataWin32.Application.Agent.CBIB18
CynetMalicious (score: 100)
McAfeeArtemis!72828E7DCEF0
VBA32Trojan.MulDrop
MalwarebytesMalware.Heuristic.1003
PandaTrj/CI.A
RisingPUA.Presenoker!8.F608 (CLOUD)
YandexRiskware.Agent!2xF+O0Yw5yI
IkarusPUA.CommandCam
FortinetW32/CommandCam.A
AVGScript:SNH-gen [Trj]
AvastScript:SNH-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan-Spy.Win32.Agent.jqvo?

Trojan-Spy.Win32.Agent.jqvo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment