Categories: Trojan

Trojan.Win32.Agent.qwhgmi information

The Trojan.Win32.Agent.qwhgmi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.qwhgmi virus can do?

  • At least one process apparently crashed during execution
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates a hidden or system file
  • Checks the system manufacturer, likely for anti-virtualization
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Agent.qwhgmi?


File Info:

crc32: 1CE1371Bmd5: afb5b45c8d5464232adaaee3634da1ffname: sdas.exesha1: 658bfab942a78f8bb2fd337ac077b30ac18138d9sha256: a2cfc5af4b1716187a73f816a5b756d3fe7c07d611a379b40b00b525a587bac3sha512: 2d4ad359943c34bf852eb2d21858506fc2b3e91ba649f91a26e36deb30c6a75c0f2040d0ddd3d945b38d394b04734d006a31a6b1f0fd99372405d5fea74c416essdeep: 768:Q9J8NowRheD8/3rJiUqyet8w9abyzm5E50kyoVonvzRiZljBwiwo5sW3LhaNIC4s:Q9wvQUreUbyzABq2mLha2Oeotype: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Agent.qwhgmi also known as:

Bkav W32.BacdotdY.Trojan
MicroWorld-eScan Trojan.GenericKD.40473581
CAT-QuickHeal Trojan.IGENERIC
McAfee RDN/Generic.tfr
Zillya Trojan.Agent.Win32.959955
BitDefender Trojan.GenericKD.40473581
K7GW Riskware ( 0040eff71 )
K7AntiVirus Riskware ( 0040eff71 )
Arcabit Trojan.Generic.D26993ED
TrendMicro TROJ_GEN.R002C0DIB18
NANO-Antivirus Riskware.Win32.TrjGen.dikprl
Cyren W32/Trojan.YRZZ-8451
Symantec ML.Attribute.HighConfidence
TrendMicro-HouseCall TROJ_GEN.R002C0DIB18
Paloalto generic.ml
ClamAV Win.Dropper.Agent-176809
GData Trojan.GenericKD.40473581
Kaspersky Trojan.Win32.Agent.qwhgmi
ViRobot Trojan.Win32.Agent.48128.BB
AegisLab Troj.Clicker.BAT.Small.lpfE
Rising Trojan.Agent!8.B1E (CLOUD)
Ad-Aware Trojan.GenericKD.40473581
Emsisoft Trojan.GenericKD.40473581 (B)
Comodo TrojWare.Win32.Trojan.Agent.~GAAC
F-Secure Trojan.GenericKD.40473581
DrWeb Tool.Siggen.6796
Invincea heuristic
McAfee-GW-Edition RDN/Generic.tfr
Sophos Mal/Generic-S
Ikarus Backdoor.Win32.SuspectCRC
Jiangmin Worm.BAT.v
Avira TR/Agent.puega
Kingsoft Win32.Hack.Generic.(kcloud)
Microsoft Trojan:Win32/Tiggre!rfn
SUPERAntiSpyware Trojan.Agent/Gen-Dropper
ZoneAlarm Trojan.Win32.Agent.qwhgmi
TACHYON Trojan/W32.DP-Agent.48640.N
AhnLab-V3 Malware/Win32.Generic.C2698789
ALYac Trojan.GenericKD.40473581
VBA32 Trojan.Agent
Cylance Unsafe
Panda Trj/CI.A
Tencent Win32.Trojan.Agent.Lrij
Fortinet W32/Agent.QWHGMI!tr
AVG FileRepMalware
Cybereason malicious.942a78
Qihoo-360 Win32/Trojan.9de

How to remove Trojan.Win32.Agent.qwhgmi?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Babar.213996 removal tips

The Babar.213996 is considered dangerous by lots of security experts. When this infection is active,…

1 min ago

Malware.AI.2248263649 (file analysis)

The Malware.AI.2248263649 is considered dangerous by lots of security experts. When this infection is active,…

11 mins ago

About “Trojan.Dropper.Agent.AKK” infection

The Trojan.Dropper.Agent.AKK is considered dangerous by lots of security experts. When this infection is active,…

18 mins ago

Malware.AI.2972915474 malicious file

The Malware.AI.2972915474 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Win32/Autoit.OPN information

The Win32/Autoit.OPN is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Malware.AI.3788326785 removal

The Malware.AI.3788326785 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago