Trojan

What is “Trojan.Win32.Agent.qwfevi”?

Malware Removal

The Trojan.Win32.Agent.qwfevi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.qwfevi virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 127.0.0.1:6039
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
ping3.teamviewer.com
master8.teamviewer.com
US-SJC-IBM-R029.teamviewer.com

How to determine Trojan.Win32.Agent.qwfevi?


File Info:

crc32: DC4D69C7
md5: a900dd64b9be551600f4ca851bd25f88
name: 20180311twam-hackhw.com-heiyu.exe
sha1: 7a50afd5c4cb96665668a869e4f955b676fdf1ff
sha256: a477c252d5a123c1aafc26f9ab241a1fa0a3eb8c826325a2d308ba4d5b28620d
sha512: ff72a79be19a1e137ffde4ee5f48e1126e6353de50e904cdfa32c6efdb74b5c2f7c70a8fdfb8e032b5c1f3b1054e14ec7506f807132ef5365e653c2c22b6efc2
ssdeep: 393216:cdSQ81U9tVx6Y78UlYYDPUfCE8m4A5KBlupw:cdx81Cjxd7PxDScAmuy
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: TeamViewer Remote Control Application
FileVersion: 13.0.6447.0
CompanyName: TeamViewer GmbH
LegalTrademarks: TeamViewer
ProductName: TeamViewer
FileDescription: TeamViewer Enterprise Portable
OriginalFilename: TeamViewer.exe
Translation: 0x0804 0x03a8

Trojan.Win32.Agent.qwfevi also known as:

CAT-QuickHealTrojan.Agent
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Agent.4!c
TrendMicroTROJ_GEN.R011C0OCF19
TrendMicro-HouseCallTROJ_GEN.R011C0OCF19
KasperskyTrojan.Win32.Agent.qwfevi
AlibabaTrojan:Win32/Agent.abae6d3f
NANO-AntivirusTrojan.Win32.Mlw.ezibbv
F-SecureTrojan.TR/Agent.bwbuu
ZillyaTrojan.Agent.Win32.874371
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.BadFile.wc
WebrootW32.Trojan.Gen
AviraTR/Agent.bwbuu
MAXmalware (ai score=96)
MicrosoftTrojan:Win32/Occamy.C
Endgamemalicious (high confidence)
ZoneAlarmTrojan.Win32.Agent.qwfevi
GDataWin32.Trojan.Agent.VVTVS4
McAfeeArtemis!A900DD64B9BE
VBA32Trojan.Agent
CylanceUnsafe
PandaTrj/CI.A
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Trojan.Win32.Agent.qwfevi?

Trojan.Win32.Agent.qwfevi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment