Trojan

Trojan:Win32/Agent.QN information

Malware Removal

The Trojan:Win32/Agent.QN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Agent.QN virus can do?

  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Attempts to stop active services
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Created a service that was not started
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Trojan:Win32/Agent.QN?


File Info:

crc32: 3E0A0D3B
md5: ccbe1775eb280c1b6187628534fc34da
name: CCBE1775EB280C1B6187628534FC34DA.mlw
sha1: e6fd82f5b0d4db6e08f1b6d73e55c9224e14e53e
sha256: 2a78a8a9bae302f1f588d5ad056f33d0fb23d5af1d37b53d9bbe93faa7bbdd2c
sha512: 429fc9f21b5b482fdf00cb40d92bd80df8156da85f98443a37fabcde96cbde7381e8a51888981ce02389394c00c217d0f600f5b01f22db5d58a80e403801fa06
ssdeep: 6144:32RfS155ONNXBuWoJBO9OMbHLkAqF7Ief9UmM7/uT:32EB0NxDIBuOFe7/uT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Agent.QN also known as:

BkavW32.AIDetect.malware2
LionicVirus.Win32.Kate.l4Cs
Elasticmalicious (high confidence)
DrWebWin32.WowSub.4
ClamAVWin.Worm.Allaple-221772
CAT-QuickHealTrojanDropper.Jadtre.B7
ALYacWorm.SillyFDC-CJ
CylanceUnsafe
ZillyaDropper.Bototer.Win32.1394
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/Bototer.244d31cc
K7GWP2PWorm ( 0012a1cd1 )
K7AntiVirusTrojan-Downloader ( 0012a1cd1 )
BaiduWin32.Trojan-Downloader.Agent.h
CyrenW32/Risk.MODP-1101
SymantecW32.SillyFDC
ESET-NOD32Win32/AutoRun.AntiAV.T
APEXMalicious
AvastWin32:AutoRun-BFB [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Dropper.Win32.Bototer.bff
BitDefenderGen:Variant.Doina.8580
NANO-AntivirusTrojan.Win32.WowSub.etjuvq
ViRobotTrojan.Win32.A.Downloader.248832.DJ
MicroWorld-eScanGen:Variant.Doina.8580
TencentTrojan.Win32.Qvod.c
Ad-AwareGen:Variant.Doina.8580
SophosML/PE-A + Mal/Jadtre-C
ComodoTrojWare.Win32.TrojanDropper.Small.U@1ulauh
BitDefenderThetaGen:NN.ZexaF.34142.pCW@ayk7XDhb
VIPREWorm.Win32.Jadtre.a (v)
TrendMicroTROJ_JADTRE.AB
McAfee-GW-EditionBehavesLike.Win32.Pate.dc
FireEyeGeneric.mg.ccbe1775eb280c1b
EmsisoftGen:Variant.Doina.8580 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Agent.btpo
WebrootW32.Trojan.Gen
AviraW32/Diliman.B
eGambitTrojan.Generic
Antiy-AVLTrojan/Generic.ASBOL.20FC
KingsoftWin32.Infected.AutoInfector.a.(kcloud)
MicrosoftTrojan:Win32/Agent.QN
GridinsoftTrojan.Win32.Gen.bot!i
ArcabitTrojan.Doina.D2184
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
GDataWin32.Virus.Booter-Main.A
AhnLab-V3Win-Trojan/Bototer.275968
Acronissuspicious
McAfeeDownloader-CCW
MAXmalware (ai score=100)
VBA32BScope.Trojan.SvcHorse.01643
MalwarebytesAllaple.Worm.DDoS.DDS
PandaGeneric Malware
TrendMicro-HouseCallTROJ_JADTRE.AB
RisingWorm.Win32.Autorun.tsg (CLASSIC)
YandexTrojan.GenAsa!Ju64OpijAdY
IkarusTrojan-Dropper.Win32.Small
MaxSecureVirus.W32.Bototer.A
FortinetW32/KillAV.NHY!tr
AVGWin32:AutoRun-BFB [Trj]
Paloaltogeneric.ml

How to remove Trojan:Win32/Agent.QN?

Trojan:Win32/Agent.QN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment