Worm

What is “Win32.Worm.Agent.QHS”?

Malware Removal

The Win32.Worm.Agent.QHS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32.Worm.Agent.QHS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities to enumerate running processes
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32.Worm.Agent.QHS?


File Info:

name: 2C02DA495B8F713CE2C4.mlw
path: /opt/CAPEv2/storage/binaries/7333682111287ac4d8cd8b0928d0898ba7cf0117ac476db12a699000a950ae6e
crc32: 031C91AE
md5: 2c02da495b8f713ce2c47926d02f3830
sha1: 0f7f9f60393b68cc7360aa5ffe75369d69202ce9
sha256: 7333682111287ac4d8cd8b0928d0898ba7cf0117ac476db12a699000a950ae6e
sha512: 0a12cd8587847866f9c2597e87e153a4cc2120f8a05da7eee05f4299fb21ec9b86b3186548f5b7d557ca3d44bbd7023c8a054b271595535005ca086002e35b3a
ssdeep: 12288:jSFMFpuhRp8tmnkX4C4IosE/rSkU19Zt/kMM22:mF+u+gkX3o1jSkErM2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BBB412332508C82BC281C5F15E6587E97A2B6F2593116E07A599FE882176CC37FF522E
sha3_384: 4148b5af2c37bae9674c6c4edffd32ecd16b3113b4d4d836a0ae5bdadeb2735ce84c41047a49bd012165f50f88d004f7
ep_bytes: 68601b4000e8f0ffffff000048000000
timestamp: 2012-01-18 20:37:40

Version Info:

0: [No Data]

Win32.Worm.Agent.QHS also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Diple.lt2E
tehtrisGeneric.Malware
MicroWorld-eScanWin32.Worm.Agent.QHS
FireEyeGeneric.mg.2c02da495b8f713c
CAT-QuickHealVirTool.Vbinder.Gen
ALYacWin32.Worm.Agent.QHS
CylanceUnsafe
ZillyaTrojan.Diple.Win32.45719
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
AlibabaTrojanDropper:Win32/Diple.12693f45
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.95b8f7
BitDefenderThetaGen:NN.ZevbaF.34698.GqW@aKWsSJoi
VirITTrojan.Win32.Generic.UZZ
CyrenW32/VBloader.I.gen!Eldorado
SymantecTrojan.Dropper
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDropper.VB.OAA
BaiduWin32.Trojan-Dropper.VB.ac
TrendMicro-HouseCallTROJ_DIPLE.SMIC
Paloaltogeneric.ml
ClamAVWin.Packer.VBCrypt-5731541-0
KasperskyTrojan.Win32.Diple.emhu
BitDefenderWin32.Worm.Agent.QHS
NANO-AntivirusTrojan.Win32.Agent.mjxpp
CynetMalicious (score: 100)
SUPERAntiSpywareTrojan.Agent/Gen-Frokon
APEXMalicious
TencentWorm.Win32.Vobfus.n
Ad-AwareWin32.Worm.Agent.QHS
SophosML/PE-A + Troj/VB-FSV
ComodoTrojWare.Win32.Agent.CIF@4m8wu5
DrWebTrojan.VbCrypt.85
VIPREWin32.Worm.Agent.QHS
TrendMicroTROJ_DIPLE.SMIC
Trapminemalicious.high.ml.score
EmsisoftWin32.Worm.Agent.QHS (B)
IkarusTrojan.Win32.Sirefef
GDataWin32.Worm.Agent.QHS
WebrootW32.Worm.P2p
AviraTR/Dropper.Gen
MAXmalware (ai score=99)
Antiy-AVLTrojan/Win32.Diple.emhu
ViRobotTrojan.Win32.A.Diple.536576
MicrosoftVirTool:Win32/VBInject
GoogleDetected
AhnLab-V3Worm/Win32.AutoRun.R19665
McAfeeVBObfus.da
VBA32BScope.Trojan.VBCR.2712
MalwarebytesTrojan.Zbot
AvastWin32:AutoRun-COG [Trj]
RisingTrojan.VB!1.65A7 (CLASSIC)
YandexTrojan.GenAsa!D4m+nvH8YBE
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.W32.WBNA.bul
FortinetW32/Dropper.ZKU!tr
AVGWin32:AutoRun-COG [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32.Worm.Agent.QHS?

Win32.Worm.Agent.QHS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment