Trojan

Should I remove “Win32/TrojanDropper.Agent.QAB”?

Malware Removal

The Win32/TrojanDropper.Agent.QAB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDropper.Agent.QAB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • A named pipe was used for inter-process communication
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file

How to determine Win32/TrojanDropper.Agent.QAB?


File Info:

name: 795B20AAFBBCC5121102.mlw
path: /opt/CAPEv2/storage/binaries/0ed2d32f1c1c03cd8645d6bd066b6b5dd98b00bd5f82774a240b86c99a9f8281
crc32: 6C2FBBFD
md5: 795b20aafbbcc512110263ef85177cf5
sha1: 1f443329491957678222336cf982ce0c2552fccb
sha256: 0ed2d32f1c1c03cd8645d6bd066b6b5dd98b00bd5f82774a240b86c99a9f8281
sha512: 4b1a1101e10a4d7763053ee1dd27ff4a5713a3bb53879618817f4184330c029901ea1e3402a0ebf79fb685e531931ab8ce100d363f5eec942bc282901965157a
ssdeep: 3072:zP3o/ufgfaFMbK3MFN4/cudLUu/4x0lhZ8nTxjDCWMpmPkR2U+tR3dDMm2WKis:zgmfgAwZjxFMMPkRsflBKP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17FC37C91FF0B183DF6080079ECA9CB5FAD5AB5D483AD56C5E2882E60CFF356852913C9
sha3_384: c6d62f8c2f1e2f31011a83757adcde3c09f16ec1221c50b879defaebed39a33769682c281ff1e819e3d077069842b3ac
ep_bytes: 558bec6aff6868c24000688eb3400064
timestamp: 2012-12-07 02:24:11

Version Info:

0: [No Data]

Win32/TrojanDropper.Agent.QAB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.hqW@Iz0Frxeb
ALYacGen:Trojan.Heur.hqW@Iz0Frxeb
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
AlibabaTrojanDropper:Win32/BScope.26b71690
CrowdStrikewin/malicious_confidence_100% (W)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.QAB
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Trojan.Heur.hqW@Iz0Frxeb
NANO-AntivirusTrojan.Win32.Agent.dandyz
AvastWin32:Dropper-gen [Drp]
TencentWin32.Trojan.Heur.Ahyp
Ad-AwareGen:Trojan.Heur.hqW@Iz0Frxeb
EmsisoftGen:Trojan.Heur.hqW@Iz0Frxeb (B)
ComodoMalware@#awot5qz69jsw
F-SecureHeuristic.HEUR/AGEN.1246248
ZillyaDropper.Agent.Win32.387817
TrendMicroTROJ_GEN.R002C0WF522
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.795b20aafbbcc512
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Heur.hqW@Iz0Frxeb
WebrootW32.Malware.gen
AviraHEUR/AGEN.1246248
MAXmalware (ai score=82)
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Heur.ED1828D
ViRobotTrojan.Win32.Z.Agent.118784.CBP
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftPWS:Win32/Zbot!ml
CynetMalicious (score: 100)
McAfeeArtemis!795B20AAFBBC
VBA32BScope.Trojan.Downloader
MalwarebytesMachineLearning/Anomalous.100%
TrendMicro-HouseCallTROJ_GEN.R002C0WF522
RisingDropper.Agent!8.2F (RDMK:cmRtazrtvG9+3myKT3EavBHmaKAu)
YandexTrojan.GenAsa!2c81kXFaors
IkarusTrojan-Dropper.Win32.Agent
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Agent.QAB!tr
BitDefenderThetaAI:Packer.F24020811C
AVGWin32:Dropper-gen [Drp]
Cybereasonmalicious.afbbcc

How to remove Win32/TrojanDropper.Agent.QAB?

Win32/TrojanDropper.Agent.QAB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment