Malware

Win32/Agent.TQO malicious file

Malware Removal

The Win32/Agent.TQO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Agent.TQO virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality

How to determine Win32/Agent.TQO?


File Info:

name: 84C26A85E46140D37B0C.mlw
path: /opt/CAPEv2/storage/binaries/af799d0a152ec232ff23cdd14f10c7b99225765ff22b22ed2e6167e135ca69d7
crc32: 59552A5B
md5: 84c26a85e46140d37b0c05b9ad40013a
sha1: 0ba9db1cd0bf42a287e7629de1d6542242a7622d
sha256: af799d0a152ec232ff23cdd14f10c7b99225765ff22b22ed2e6167e135ca69d7
sha512: 70368a89d07bcaade26a4a87954ba36c876a02f11d56ed947d0ec3496d190a3778bc11e89ab429513da256ea585470215a872b628da8c35a7e079212f941b567
ssdeep: 768:C/kiRAHRn7G0JcahoLBigjew5GZ8cid7kBuz7irPnUZshx5zZemmbfErybN6:Hc0osgYC1dkBuqLnUZsh3zkmz
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12883E890BD86ADBBEA2D533CA5F392A156BDFDD04B12CB171470ED310682FD12EE0646
sha3_384: a41d124490774f893ffa0d1de00b2fc020cd5a0dd5731f45edb2204a4be3647c5dd3da106ed4f885526ee64331bccf2d
ep_bytes: 83ec0cc7059853400000000000e8be03
timestamp: 2017-11-26 21:32:34

Version Info:

0: [No Data]

Win32/Agent.TQO also known as:

SangforTrojan.Win32.Agent.TQO
BitDefenderThetaGen:NN.ZexaF.34682.f8Y@a8CTIbb
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.TQO
CynetMalicious (score: 99)
NANO-AntivirusTrojan.Win32.Generic.ivvbiy
Trapminemalicious.high.ml.score
IkarusTrojan.Win32.Agent
AviraHEUR/AGEN.1231917
VBA32BScope.Trojan.Occamy
YandexTrojan.GenAsa!TpMzz+hKWCE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.TQQ!tr
Cybereasonmalicious.cd0bf4

How to remove Win32/Agent.TQO?

Win32/Agent.TQO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment