Trojan

Trojan.Win32.Agent.ijrq (file analysis)

Malware Removal

The Trojan.Win32.Agent.ijrq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.ijrq virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time

How to determine Trojan.Win32.Agent.ijrq?


File Info:

name: C2D5F3B0ED47C0D4E412.mlw
path: /opt/CAPEv2/storage/binaries/69892a3a4d5083f9a7cb561b4c4df32a9bca7bfbd91c5d720fe60ffcb63dc0fa
crc32: AD04BD06
md5: c2d5f3b0ed47c0d4e4127780d4cf656d
sha1: c1b14c5186772dea8105dd21a8ca212f044f32fd
sha256: 69892a3a4d5083f9a7cb561b4c4df32a9bca7bfbd91c5d720fe60ffcb63dc0fa
sha512: bb66a379a153b46603be8a416ef8f785fbba70421cf3ac7610012e8008d54e7c8685e7432181fb0c3349ba0bf14e59c3923d8aaf5a1f6122ff2c8a00f429be24
ssdeep: 12288:dtb20Qc3lT7af41ePBRYuQLKpqeUhbTv5OFgNuPPpHSgaF7Le6A:dtb20pkaCqT5TBWgNQ7aZLe6A
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C2059E1373DD8361C3B25273BA25B701AEBF782506A5F96B2FD4093DE920122525EB73
sha3_384: 0f898a4f3f6c0a3d75265ffb0c6ec8c3f34e9a7660e11a5aa352406aea633051a024f00e3a0ddb61404ae8bf0eedaa5c
ep_bytes: e86ace0000e97ffeffffcccc57568b74
timestamp: 2015-08-29 08:24:20

Version Info:

Translation: 0x0809 0x04b0

Trojan.Win32.Agent.ijrq also known as:

LionicTrojan.Win32.Agent.4!c
MicroWorld-eScanTrojan.GenericKD.4862340
FireEyeTrojan.GenericKD.4862340
McAfeeArtemis!C2D5F3B0ED47
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:BAT/based.e6eea877
K7GWRiskware ( 0040eff71 )
SymantecTrojan.Gen.2
ESET-NOD32BAT/RA-based.CX
KasperskyTrojan.Win32.Agent.ijrq
BitDefenderTrojan.GenericKD.4862340
NANO-AntivirusTrojan.Win32.Agent.enyewo
Ad-AwareTrojan.GenericKD.4862340
EmsisoftTrojan.GenericKD.4862340 (B)
DrWebBackDoor.RMS.67
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.PUPXDO.ch
SophosMal/Generic-S
APEXMalicious
GDataTrojan.GenericKD.4862340
AviraTR/YahLover.gline.1
ArcabitTrojan.Generic.D4A3184
MicrosoftTrojan:Win32/Occamy.C69
CynetMalicious (score: 99)
VBA32Trojan.Agent
ALYacTrojan.GenericKD.4862340
MAXmalware (ai score=100)
TencentWin32.Trojan.Agent.Szbh
IkarusTrojan.BAT.RA
WebrootPua.Downloadmanager
Cybereasonmalicious.0ed47c
PandaTrj/CI.A

How to remove Trojan.Win32.Agent.ijrq?

Trojan.Win32.Agent.ijrq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment