Malware

Downloader.Win32.QDov.b removal guide

Malware Removal

The Downloader.Win32.QDov.b is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.QDov.b virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Downloader.Win32.QDov.b?


File Info:

name: 40A639611C6F1F616354.mlw
path: /opt/CAPEv2/storage/binaries/111d8eeb87de1a8d0f584e785c2e3d7947c936621e6a9bbc1dc2f200370f0b04
crc32: C9D1141E
md5: 40a639611c6f1f616354d9d89438d463
sha1: 0bae5346ed5b5ff9c3fc51d4920be7bf9168684d
sha256: 111d8eeb87de1a8d0f584e785c2e3d7947c936621e6a9bbc1dc2f200370f0b04
sha512: 723dfa6715079d4508cd3068e193580adcfd5c5642f24f914a283b1f6dcbcf06976ad61de8753984b99cdbed08df49351dae05cba0ac963a79f02f1844ffc73a
ssdeep: 6144:hOPjS+y6s++X1OIgFFeta2gszoIupElhOVYs+fnPpyx:KhslIIgF92qzp+EVPQg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T108C4E09425C4547AD6E6477245BBDF34E2379F9E2AB1924F0B013FB93B3B2839856083
sha3_384: a89551b5c8a6122a4dd12e29ea61a822c2bd954a436f7cb8595e6e87ab82aeed18d97e7b17ca351e373d7aaf603645d6
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-06-18 21:33:27

Version Info:

0: [No Data]

Downloader.Win32.QDov.b also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanTrojan.GenericKD.30945813
ClamAVWin.Trojan.Agent-414746
FireEyeTrojan.GenericKD.30945813
CAT-QuickHealTrojan.Rimod.A.mue
ALYacTrojan.GenericKD.30945813
CylanceUnsafe
VIPRETrojan.GenericKD.30945813
SangforPUP.Win32.XchsInstaller.8
K7AntiVirusRiskware ( 0040eff71 )
K7GWTrojan ( 0040f2131 )
CrowdStrikewin/malicious_confidence_90% (W)
VirITTrojan.Win32.DownLoader9.XSJ
CyrenW32/Agent.HVZR-0851
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32Win32/XchsInstaller.A potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:Downloader.Win32.QDov.b
BitDefenderTrojan.GenericKD.30945813
NANO-AntivirusRiskware.Nsis.Dwn.ctxiux
SUPERAntiSpywarePUP.XchsInstaller/Variant
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.30945813
EmsisoftTrojan.GenericKD.30945813 (B)
DrWebTrojan.DownLoader9.16025
ZillyaTrojan.Generic.Win32.1646192
TrendMicroTROJ_GEN.R002C0OIK22
McAfee-GW-EditionBehavesLike.Win32.AdwareAdload.hz
SophosGeneric PUA AL (PUA)
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.30945813
AviraHEUR/AGEN.1233702
Antiy-AVLTrojan/Generic.ASMalwNS.2846
ArcabitTrojan.Generic.D1D83215
ZoneAlarmnot-a-virus:Downloader.Win32.QDov.b
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
McAfeeArtemis!8DA481ACB7CE
MAXmalware (ai score=88)
VBA32Downloader.QDov
MalwarebytesNimnul.Virus.FileInfector.DDS
TrendMicro-HouseCallTROJ_GEN.R002C0OIK22
YandexTrojan.GenAsa!XY2CjdHf50M
AVGWin32:Malware-gen
Cybereasonmalicious.11c6f1
PandaTrj/NsisDownloader.A

How to remove Downloader.Win32.QDov.b?

Downloader.Win32.QDov.b removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment