Trojan

What is “Win32/TrojanDropper.Agent.PQT”?

Malware Removal

The Win32/TrojanDropper.Agent.PQT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDropper.Agent.PQT virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Code injection with CreateRemoteThread in a remote process
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net
crl.verisign.com

How to determine Win32/TrojanDropper.Agent.PQT?


File Info:

name: 21C53058D0DDF8CED29F.mlw
path: /opt/CAPEv2/storage/binaries/7abd1ff7db338cb37fe042e535a1883bae5c23010e2e64146700a25dc6efd820
crc32: D6143AF4
md5: 21c53058d0ddf8ced29ff4b5397fbaa0
sha1: 2bafe2fd1a1ad6b3ba0b1919b78dc17c08fe17dc
sha256: 7abd1ff7db338cb37fe042e535a1883bae5c23010e2e64146700a25dc6efd820
sha512: a8616be911d512bd2cc19dfd0ef18a35f9bc68c34cac07f7e9a2f3b8d9b1b10e5273e1fd8d5cf6ea9503143aea7bc35d5779103ac0a93b04421a4449a3ec741f
ssdeep: 3072:pDU8w4FwmchS6VLwmmQ4a2tjhfBUJi85aD+MAyqt395xm51rsE6RjR/AHpWiUk7d:pDU8wOwmchlVLoQ6jhfyaDyXLC5pdUkx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A55439213280C072E356173589A5D6F04A6D7D3917A5A98FFAE83E794F712D39A3320F
sha3_384: 20158db072a3b565c24bc9443fb0ee7769e3174a26daa7b09a19fafaec336278fdf96c7ad4c747898531662b3fd95637
ep_bytes: e83f520000e979feffff3b0db4e14200
timestamp: 2015-11-05 02:44:18

Version Info:

FileDescription: WinElevate
FileVersion: 3, 0, 0, 0
InternalName: WinElevate
LegalCopyright: Copyright (C) 2015, all rights reserved.
OriginalFilename: WinElevate.exe
ProductName: WinElevate
ProductVersion: 3, 0, 0, 0
Translation: 0x0809 0x04b0

Win32/TrojanDropper.Agent.PQT also known as:

LionicTrojan.Win32.UACSkip.3!c
Elasticmalicious (high confidence)
McAfeeRDN/Generic Exploit
CylanceUnsafe
K7AntiVirusTrojan ( 00333de31 )
AlibabaExploit:Win32/UACSkip.0bd00390
K7GWTrojan ( 00333de31 )
Cybereasonmalicious.8d0ddf
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.PQT
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyUDS:Exploit.Win32.UACSkip.gen
BitDefenderGen:Trojan.ExplorerHijack.ru1@aKbhT6mi
ViRobotTrojan.Win32.Z.Uacskip.291568
MicroWorld-eScanGen:Trojan.ExplorerHijack.ru1@aKbhT6mi
AvastFileRepMalware
Ad-AwareGen:Trojan.ExplorerHijack.ru1@aKbhT6mi
SophosGeneric ML PUA (PUA)
DrWebTrojan.KillProc.51735
ZillyaDropper.Agent.Win32.380836
TrendMicroTROJ_GEN.R03BC0PKN21
McAfee-GW-EditionRDN/Generic Exploit
FireEyeGeneric.mg.21c53058d0ddf8ce
EmsisoftGen:Trojan.ExplorerHijack.ru1@aKbhT6mi (B)
GDataGen:Trojan.ExplorerHijack.ru1@aKbhT6mi
JiangminExploit.UACSkip.ez
AviraTR/Drop.Agent.shque
Antiy-AVLTrojan/Generic.ASMalwS.1EE06E7
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.ExplorerHijack.EE0AF6
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win32.Scar.C156340
VBA32BScope.Exploit.UACSkip
ALYacGen:Trojan.ExplorerHijack.ru1@aKbhT6mi
MAXmalware (ai score=86)
TrendMicro-HouseCallTROJ_GEN.R03BC0PKN21
YandexTrojan.DR.Agent!7++eK9B8rQ4
MaxSecureTrojan.Malware.9872425.susgen
FortinetW32/Generic.AC.42C532
BitDefenderThetaGen:NN.ZedlaF.34294.cu8@a4YRFLci
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/TrojanDropper.Agent.PQT?

Win32/TrojanDropper.Agent.PQT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment