Trojan

Win32/TrojanDownloader.Agent.QMR removal guide

Malware Removal

The Win32/TrojanDownloader.Agent.QMR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Agent.QMR virus can do?

  • At least one process apparently crashed during execution
  • Authenticode signature is invalid

How to determine Win32/TrojanDownloader.Agent.QMR?


File Info:

name: 9588D8BD6AE1F36A6D48.mlw
path: /opt/CAPEv2/storage/binaries/c7807d3c22648e077793fefd58b35dda95b125a8ac3d7dc731933607c171f5a2
crc32: 1E94FBE7
md5: 9588d8bd6ae1f36a6d4802397bb2075a
sha1: 9b28f52f2b4fab3cc89f207d3db27ea4fe0c4906
sha256: c7807d3c22648e077793fefd58b35dda95b125a8ac3d7dc731933607c171f5a2
sha512: d38a320f2df1993a148aadf11d4ff9394a17ab3bd963fd58973aead8afdfcd3cd47fccc7703c398ace20509e35fc20e6aada18fa2e84751840adb1f90a0e6c41
ssdeep: 768:hBl0LXv/pSda7NT5GAGEf1rC6qUXJVJNFu0FETZHECtY0:hBiLXvBea7NTJf1r8YPi0C3tY0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DB138D1235E2C1F3C4C642B158A5CF2EDF7F6A32073584A39B946D9B2E752E1952B383
sha3_384: 4c2a3a2f10c288ef8cb9eb242504133c74b5f4dced0d981b71a2e5ca2288f23267bf287e818d8de8665586902dcbb33c
ep_bytes: 558bec6aff687871400068ec34400064
timestamp: 2011-01-15 22:01:13

Version Info:

0: [No Data]

Win32/TrojanDownloader.Agent.QMR also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader1.55794
MicroWorld-eScanGen:Trojan.Heur.RP.cmW@buwzQMm
FireEyeGeneric.mg.9588d8bd6ae1f36a
CAT-QuickHealWorm.Autorun.6557
ALYacGen:Trojan.Heur.RP.cmW@buwzQMm
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan-Downloader ( 0055e3da1 )
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
BitDefenderThetaAI:Packer.FCF6E2761E
VirITTrojan.Win32.Generic.JVK
CyrenW32/PcClient.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Agent.QMR
APEXMalicious
ClamAVWin.Trojan.Agent-804071
KasperskyWorm.Win32.AutoRun.ddyw
BitDefenderGen:Trojan.Heur.RP.cmW@buwzQMm
NANO-AntivirusTrojan.Win32.Dwn.diabf
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.10b3c2d8
Ad-AwareGen:Trojan.Heur.RP.cmW@buwzQMm
EmsisoftGen:Trojan.Heur.RP.cmW@buwzQMm (B)
ComodoWorm.Win32.AutoRun.DSQ@5rwgyt
BaiduWin32.Trojan-Downloader.Agent.co
TrendMicroTSPY_AUTORUN_CD102F69.RDXN
McAfee-GW-EditionBehavesLike.Win32.Generic.pm
SophosMal/Behav-027
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Heur.RP.cmW@buwzQMm
JiangminWorm/AutoRun.agvd
WebrootW32.Malware.Gen
AviraTR/Hijacker.Gen
ArcabitTrojan.Heur.RP.E5C2CF
ViRobotWorm.Win32.A.AutoRun.45056.AC
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.AutoRun.R151333
Acronissuspicious
McAfeeArtemis!9588D8BD6AE1
MAXmalware (ai score=80)
VBA32Worm.AutoRun
TrendMicro-HouseCallTSPY_AUTORUN_CD102F69.RDXN
RisingTrojan.Generic@AI.78 (RDMK:cmRtazqmOrNRGO880fS46DCh0lp+)
YandexTrojan.GenAsa!6rlaglNPlgE
IkarusWorm.Win32.AutoRun
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/Generic.AC.1209A4!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.d6ae1f

How to remove Win32/TrojanDownloader.Agent.QMR?

Win32/TrojanDownloader.Agent.QMR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment