Spy

Win32/Spy.Agent.QER removal tips

Malware Removal

The Win32/Spy.Agent.QER is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Agent.QER virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • CAPE detected the WobbyChipMBR malware family
  • Attempted to write directly to a physical drive
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Spy.Agent.QER?


File Info:

name: 20A835D9F94238AA81A2.mlw
path: /opt/CAPEv2/storage/binaries/28b713ddfd5d219993fc67a6b7434af63b2eb5cca1dd488a39ab007b751a50da
crc32: D01F687B
md5: 20a835d9f94238aa81a274f1159b8904
sha1: 654086e1f4b36487d17a78559ea6e081ed31e56a
sha256: 28b713ddfd5d219993fc67a6b7434af63b2eb5cca1dd488a39ab007b751a50da
sha512: b16da879fbed5690e6971b441f9efaf031458bcb096fe48834b25b7fdf47bfb82f70277a81d7478a7c3b816d4d51ffcc992391858a642feb2d7a558325ce5a01
ssdeep: 12288:0StYXLbMgZDQJT3S1Gzfizbm8cFKH5T3kuqzmNMSzAKl2l7vyv9fc8Cq4akGP/6B:0SIUg+dzaG9Ix3kXQzjls76vt3Y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19245E952EBC70DB7D8D727B4A4C7531A6738BD208A36DF5AE7084532DEA37C1990A702
sha3_384: 4c6b2ff4e35300db4b09cfe8d25e794e5379c4269899c21defb3baa1c5a32eb48eef2ae12569c19f54ead273f0129403
ep_bytes: 5589e583ec18c7042402000000ff152c
timestamp: 2021-10-22 10:04:45

Version Info:

0: [No Data]

Win32/Spy.Agent.QER also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2527794
K7AntiVirusTrojan ( 0055f5981 )
K7GWTrojan ( 0055f5981 )
Cybereasonmalicious.1f4b36
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Agent.QER
APEXMalicious
ClamAVWin.Malware.Ulise-7669076-0
KasperskyHEUR:Trojan.Win32.Generic
AvastWin32:Trojan-gen
RisingTrojan.KillMBR!1.C48A (CLASSIC)
DrWebMULDROP.Trojan
FireEyeGeneric.mg.20a835d9f94238aa
IkarusTrojan.Win32.KillMBR
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
VBA32BScope.Trojan.DiskWriter
MalwarebytesMalware.AI.3999972186
SentinelOneStatic AI – Malicious PE
BitDefenderThetaGen:NN.ZexaF.34294.n9Z@amf98yb
AVGWin32:Trojan-gen
PandaTrj/GdSda.A

How to remove Win32/Spy.Agent.QER?

Win32/Spy.Agent.QER removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment