Trojan

Trojan.Win32.Agent.qwhgmi information

Malware Removal

The Trojan.Win32.Agent.qwhgmi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.qwhgmi virus can do?

  • At least one process apparently crashed during execution
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates a hidden or system file
  • Checks the system manufacturer, likely for anti-virtualization
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Agent.qwhgmi?


File Info:

crc32: 1CE1371B
md5: afb5b45c8d5464232adaaee3634da1ff
name: sdas.exe
sha1: 658bfab942a78f8bb2fd337ac077b30ac18138d9
sha256: a2cfc5af4b1716187a73f816a5b756d3fe7c07d611a379b40b00b525a587bac3
sha512: 2d4ad359943c34bf852eb2d21858506fc2b3e91ba649f91a26e36deb30c6a75c0f2040d0ddd3d945b38d394b04734d006a31a6b1f0fd99372405d5fea74c416e
ssdeep: 768:Q9J8NowRheD8/3rJiUqyet8w9abyzm5E50kyoVonvzRiZljBwiwo5sW3LhaNIC4s:Q9wvQUreUbyzABq2mLha2Oeo
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Agent.qwhgmi also known as:

BkavW32.BacdotdY.Trojan
MicroWorld-eScanTrojan.GenericKD.40473581
CAT-QuickHealTrojan.IGENERIC
McAfeeRDN/Generic.tfr
ZillyaTrojan.Agent.Win32.959955
BitDefenderTrojan.GenericKD.40473581
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
ArcabitTrojan.Generic.D26993ED
TrendMicroTROJ_GEN.R002C0DIB18
NANO-AntivirusRiskware.Win32.TrjGen.dikprl
CyrenW32/Trojan.YRZZ-8451
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0DIB18
Paloaltogeneric.ml
ClamAVWin.Dropper.Agent-176809
GDataTrojan.GenericKD.40473581
KasperskyTrojan.Win32.Agent.qwhgmi
ViRobotTrojan.Win32.Agent.48128.BB
AegisLabTroj.Clicker.BAT.Small.lpfE
RisingTrojan.Agent!8.B1E (CLOUD)
Ad-AwareTrojan.GenericKD.40473581
EmsisoftTrojan.GenericKD.40473581 (B)
ComodoTrojWare.Win32.Trojan.Agent.~GAAC
F-SecureTrojan.GenericKD.40473581
DrWebTool.Siggen.6796
Invinceaheuristic
McAfee-GW-EditionRDN/Generic.tfr
SophosMal/Generic-S
IkarusBackdoor.Win32.SuspectCRC
JiangminWorm.BAT.v
AviraTR/Agent.puega
KingsoftWin32.Hack.Generic.(kcloud)
MicrosoftTrojan:Win32/Tiggre!rfn
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
ZoneAlarmTrojan.Win32.Agent.qwhgmi
TACHYONTrojan/W32.DP-Agent.48640.N
AhnLab-V3Malware/Win32.Generic.C2698789
ALYacTrojan.GenericKD.40473581
VBA32Trojan.Agent
CylanceUnsafe
PandaTrj/CI.A
TencentWin32.Trojan.Agent.Lrij
FortinetW32/Agent.QWHGMI!tr
AVGFileRepMalware
Cybereasonmalicious.942a78
Qihoo-360Win32/Trojan.9de

How to remove Trojan.Win32.Agent.qwhgmi?

Trojan.Win32.Agent.qwhgmi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment