Malware

Win32/Agent.QMU removal

Malware Removal

The Win32/Agent.QMU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.QMU virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32/Agent.QMU?


File Info:

name: 73133C1A82234B0AFF66.mlw
path: /opt/CAPEv2/storage/binaries/cf272848efca06724c673b84d2927c96af66bd7451e7d28ffb727c30e30d1b54
crc32: F00579E7
md5: 73133c1a82234b0aff66a7c5cb4e94a1
sha1: f1da43cf4bda92462d8f23c0e7ac43042305722b
sha256: cf272848efca06724c673b84d2927c96af66bd7451e7d28ffb727c30e30d1b54
sha512: 256a93444b9c748855aa51804d5434ce5082648683a4b4384353fba64ff7c26ee51cde21feed4a3b6cba3102008392993eacf7f7aaad39595d74da5493b3a46d
ssdeep: 1536:ksi1sTmwHiMQgISgYwnNB4W7hRx87FXLlylnouy8NT3qCZQX2oooD+AyxArXIVJI:tiu1gYy34myK9outNTaIQXMmXIM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14063D053AF846E9EE83905381CDBED4A0D24DCCDDCD0CA6695887C335D7BB5A253E212
sha3_384: 70c82a711595647c24b847ee619c08847ef15d8e52ef517095172cabd8cb737d49b9f1dd1b7c4aef51d4ae687785c8a1
ep_bytes: 60be004041008dbe00d0feff5789e58d
timestamp: 2014-09-09 01:07:22

Version Info:

Comments:
CompanyName:
FileDescription: Microsoft(R) Windows(R) Operating System
FileVersion: 6, 0, 2900, 5512
InternalName:
LegalCopyright: 版权所有 (C) 2013
LegalTrademarks:
OriginalFilename:
PrivateBuild:
ProductName: Microsoft
ProductVersion: 6.00.2900.5512
SpecialBuild:
Translation: 0x0804 0x04b0

Win32/Agent.QMU also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Trojan.Heur.emKfrn@jXAlbh
ClamAVWin.Trojan.Agent-1362721
FireEyeGeneric.mg.73133c1a82234b0a
ALYacGen:Trojan.Heur.emKfrn@jXAlbh
K7AntiVirusTrojan ( 0040f91f1 )
K7GWTrojan ( 0040f91f1 )
Cybereasonmalicious.a82234
BaiduWin32.Trojan.Kryptik.gp
CyrenW32/Trojan-Gypikon-based.BA!Max
ESET-NOD32a variant of Win32/Agent.QMU
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Trojan.Heur.emKfrn@jXAlbh
NANO-AntivirusTrojan.Win32.PolyCrypt.dpmiea
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.10b2d6f6
EmsisoftGen:Trojan.Heur.emKfrn@jXAlbh (B)
F-SecureTrojan.TR/Crypt.CFI.Gen
DrWebBackDoor.PcClient.6500
VIPREGen:Trojan.Heur.emKfrn@jXAlbh
McAfee-GW-EditionBehavesLike.Win32.Generic.lc
Trapminemalicious.high.ml.score
SophosML/PE-A
SentinelOneStatic AI – Suspicious PE
GDataGen:Trojan.Heur.emKfrn@jXAlbh
WebrootW32.Worm.Morto.E
AviraTR/Crypt.CFI.Gen
Antiy-AVLTrojan[Packed]/Win32.Gena.b
XcitiumTrojWare.Win32.Amtar.MUVP@5hqavh
ArcabitTrojan.Heur.E933C5
ZoneAlarmPacked.Win32.Gena.b
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.1Table.R120825
McAfeeGenericRXEY-BF!73133C1A8223
MAXmalware (ai score=81)
VBA32TScope.Malware-Cryptor.SB
PandaTrj/Genetic.gen
RisingBackdoor.Win32.Dunsenr.bb (CLASSIC)
YandexTrojan.GenAsa!X5ipN92tsx8
IkarusTrojan.Win32.Agent2
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.5325!tr
BitDefenderThetaAI:Packer.B0A530DD1D
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Win32/Agent.QMU?

Win32/Agent.QMU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment