Trojan

Trojan.Win32.Agentb.bqyr removal

Malware Removal

The Trojan.Win32.Agentb.bqyr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agentb.bqyr virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Sniffs keystrokes
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Agentb.bqyr?


File Info:

crc32: 992EF61B
md5: 714b7a670e8856cc5e1f12439c0cd8d8
name: 714B7A670E8856CC5E1F12439C0CD8D8.mlw
sha1: e1f8e66e05b2b8e064768abeb024c76bf3b6fddf
sha256: d7cdf2d5b6835c47d8c705e7c723e9dc0814b79dd3acc0d1779c27d4b693842a
sha512: bef921d2ebe46f82db95b9fdebf8cdf03fcaa74e77c1add1440556f084e9d5926ad26c3ca3c987b3e1ce61b8d563de58dd1b35c3bf3eef7b26de41af7a1ff34c
ssdeep: 24576:WH3q6ctjO6Wf6ZvHB1/B4sA9f3aHt0s0u44x:866c1cyn/GsAF1sy4
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Agentb.bqyr also known as:

BkavW32.FamVT.ScarC.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.DCER
FireEyeGeneric.mg.714b7a670e8856cc
CAT-QuickHealWorm.Macoute.A8
Qihoo-360HEUR/QVM02.0.9617.Malware.Gen
ALYacTrojan.Agent.DCER
CylanceUnsafe
ZillyaTrojan.Scar.Win32.54986
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004ba8531 )
K7GWTrojan ( 004ba8531 )
Cybereasonmalicious.70e885
CyrenW32/Trojan.KZWZ-0325
SymantecW32.Pholdicon
APEXMalicious
ClamAVWin.Trojan.Agent-1201096
KasperskyTrojan.Win32.Agentb.bqyr
BitDefenderTrojan.Agent.DCER
NANO-AntivirusTrojan.Win32.Agent.erqhdu
TencentTrojan.Win32.Keylogger.aa
Ad-AwareTrojan.Agent.DCER
SophosMal/Generic-R + Troj/Scar-CM
ComodoTrojWare.Win32.Scar.WRM@6hdckm
F-SecureTrojan.TR/Patched.Ren.Gen7
DrWebTrojan.DownLoader22.23546
VIPRETrojan.Win32.Generic!BT
TrendMicroPE_VIRUX.A-3
McAfee-GW-EditionBehavesLike.Win32.Generic.tm
EmsisoftTrojan.Agent.DCER (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Agent.DCER
JiangminTrojan/Scar.agsm
AviraTR/Patched.Ren.Gen7
Antiy-AVLTrojan/Win32.Scar
GridinsoftTrojan.Win32.Agent.bot!s1
ArcabitTrojan.Agent.DCER
ZoneAlarmTrojan.Win32.Agentb.bqyr
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Scar.R160138
Acronissuspicious
McAfeeGenericRXAH-QS!714B7A670E88
MalwarebytesPioneer.Virus.FileInfector.DDS
ESET-NOD32Win32/Agent.NML
TrendMicro-HouseCallPE_VIRUX.A-3
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazrr14FVo53eEl6pZz1PR9jM)
YandexTrojan.GenAsa!53PMqSgQMYw
IkarusWin32.Outbreak
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.NML!tr
BitDefenderThetaGen:NN.ZexaF.34590.QHW@aiC2uydi
AVGWin32:Vitro [Inf]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Agentb.bqyr?

Trojan.Win32.Agentb.bqyr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment