Malware

Win32/Agent.QZM malicious file

Malware Removal

The Win32/Agent.QZM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.QZM virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempted to write directly to a physical drive
  • Attempts to modify proxy settings
  • Created a service that was not started
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Agent.QZM?


File Info:

name: 1C5A127A63DEFD736759.mlw
path: /opt/CAPEv2/storage/binaries/6e4c9362d078cbe6ba61c7c41c763a8e2a6b5560e79a83d0f4cfb33b67dad61a
crc32: E448F387
md5: 1c5a127a63defd7367591546cd19e233
sha1: e66d327b660f896ad3bb612fc01d11aa9e83d886
sha256: 6e4c9362d078cbe6ba61c7c41c763a8e2a6b5560e79a83d0f4cfb33b67dad61a
sha512: badd7a5c80cfbb6f7de2bd5fd03cce32446bb4e21ede5ade85aebc97e486691c1dd430979c4726572862ed5c48e6ef41ba939998b4df2769fabe09f51aec3bfa
ssdeep: 24576:f2qu8smCy3KxW3ixPEmxsvGrm8Z6r+JQPzV7GoMP:fFKW3Rm2vGaCJQ7soMP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D7259D11B6D1C073C0B211300669DB764D7BB971153594ABBBE88E3E1F743C1EA27BAA
sha3_384: 5aca23982353f8433c729787659330635c7ec41b884e19aeb76bec7390214fb17364ac83ed3985755f5b92bd3d9e71ee
ep_bytes: e826030000e94cfeffffff253c714000
timestamp: 2014-08-02 08:08:33

Version Info:

CompanyName: QNT
FileDescription: desktop icon
FileVersion: 2.0.0.0
InternalName: setup.exe
LegalCopyright: Copyright (C) 2014
OriginalFilename: setup.exe
ProductName: setup
ProductVersion: 2.0.0.0
Translation: 0x0804 0x04b0

Win32/Agent.QZM also known as:

DrWebAdware.Mutabaha.3315
CAT-QuickHealPUA.Beijinggao.Gen
McAfeeArtemis!F1C60FE30ECF
MalwarebytesFloxif.Virus.FileInfector.DDS
ZillyaTrojan.AgentCRTD.Win32.4805
K7AntiVirusTrojan ( 00587c5a1 )
K7GWTrojan ( 00587c5a1 )
VirITPUP.Win32.Beijing.G
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.QZM
KasperskyTrojan.Win32.Bsymem.vjz
NANO-AntivirusRiskware.Win32.Mutabaha.iuzeag
RisingTrojan.Agent!8.B1E (CLOUD)
F-SecureTrojan.TR/Agent.tomwo
McAfee-GW-EditionArtemis
AviraTR/Agent.tomwo
Antiy-AVLGrayWare/Win32.Creprote
MicrosoftPUA:Win32/Creprote
ZoneAlarmTrojan.Win32.Bsymem.vjz
VBA32SigAdware.BeijingGaojiaoxintuTechnologyCoLtd
CrowdStrikewin/grayware_confidence_70% (D)

How to remove Win32/Agent.QZM?

Win32/Agent.QZM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment