Malware

Mal/Qbot-P removal

Malware Removal

The Mal/Qbot-P is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Qbot-P virus can do?

  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Mal/Qbot-P?


File Info:

name: 1DDEA14130D3AA0B8176.mlw
path: /opt/CAPEv2/storage/binaries/76b7c37b8cbe4e7427f0a42596227d33224661792f4cc647ec372033b80e6dbd
crc32: 98CBBAEC
md5: 1ddea14130d3aa0b8176cbd56a16da18
sha1: 7bb5c57be6cc8b4f56671fc89be05ddbacba0689
sha256: 76b7c37b8cbe4e7427f0a42596227d33224661792f4cc647ec372033b80e6dbd
sha512: f944bbc72fbc445bb8612d0856ff0a8009e4a93cea1f43d11f328bf450e7c7edcf004830cbeeb8fb0b7baa217282dbf9bdaa29c59235807aeb34898f94cad06b
ssdeep: 6144:XgnfzJrDWRoI+Q/k3HYXCDxilwn9xYwgCPOdoZI6BGwfAleHYmbI:XiJrDGB++plwn9xYFOOyZNINeHYaI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BB847D22BA04F432C16240B9EA55E379A5B874312526484BF7E4CF6D9FE1392DB38B47
sha3_384: bac82238b79e4cfe5e43eb34a28d006279baa773c4e4a964cd5ded9d9a34c038a74cd2dd3980b1f4ba1f82342a53640c
ep_bytes: e8ba9f0000e978feffffcccccccccccc
timestamp: 2013-01-20 20:14:04

Version Info:

Comments:
CompanyName: Microsoft Corporation
FileDescription: Microsoft RSVP
FileVersion: 5.1.2600.0
InternalName: rsvp.exe
LegalCopyright: ᄅ Microsoft Corporation. All rights reserved.
LegalTrademarks: ᄅ Microsoft Corporation. All rights reserved.
OriginalFilename: rsvp.exe
PrivateBuild: rsvp.exe
ProductName: Microsoftᆴ Windowsᆴ Operating System
ProductVersion: 5.1.2600.0
SpecialBuild: 5.1.2600.0
Translation: 0x0409 0x04b0

Mal/Qbot-P also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.Malware.yy0@aaZ4U2pi
FireEyeGeneric.mg.1ddea14130d3aa0b
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.NetLoader.fh
McAfeeDownloader-FIK!1DDEA14130D3
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.Malware.yy0@aaZ4U2pi
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Vindor.59e2fa40
Cybereasonmalicious.be6cc8
ArcabitTrojan.Malware.E7CF48
VirITTrojan.Win32.DownLoader8.UBN
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Rodecap.BB
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Malware.yy0@aaZ4U2pi
AvastWin32:MalwareX-gen [Trj]
TencentMalware.Win32.Gencirc.10b2aee3
EmsisoftGen:Trojan.Malware.yy0@aaZ4U2pi (B)
F-SecureTrojan.TR/Small.bhoumd
DrWebTrojan.DownLoader8.13559
ZillyaTrojan.Rodecap.Win32.1703
TrendMicroTROJ_RODECAP.SMO
Trapminemalicious.moderate.ml.score
SophosMal/Qbot-P
IkarusTrojan.Win32.Small
JiangminTrojan/Generic.azpcd
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Small.bhoumd
Antiy-AVLTrojan/Win32.Unknown
XcitiumTrojWare.Win32.Agent.AWR@4ri3wg
MicrosoftTrojan:Win32/Small.BH
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Trojan.Malware.yy0@aaZ4U2pi
VaristW32/SmallDl.F.gen!Eldorado
AhnLab-V3Trojan/Win32.Blocker.R82934
Acronissuspicious
VBA32BScope.Trojan.Downloader
ALYacGen:Trojan.Malware.yy0@aaZ4U2pi
MAXmalware (ai score=83)
Cylanceunsafe
PandaGeneric Suspicious
TrendMicro-HouseCallTROJ_RODECAP.SMO
RisingRansom.Blocker!8.12A (TFE:5:bCIcjKVkMPC)
YandexTrojan.GenAsa!6KhuQuHc76g
SentinelOneStatic AI – Malicious PE
FortinetW32/Rodecap.BBC!tr
BitDefenderThetaGen:NN.ZexaF.36744.yy0@aaZ4U2pi
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Mal/Qbot-P?

Mal/Qbot-P removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment