Malware

PHP/Qhost.R removal

Malware Removal

The PHP/Qhost.R is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PHP/Qhost.R virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • The sample wrote data to the system hosts file.

How to determine PHP/Qhost.R?


File Info:

crc32: 604C8CD0
md5: a62e8deb5abe77005ff5c076854c5321
name: A62E8DEB5ABE77005FF5C076854C5321.mlw
sha1: 4e6c1cd0342c6472bc1f1f6f8bbcad61bc0fe0fc
sha256: f2147720df702e8e4b85a050bd77c710eaefbffb4e26ad770b249cd4eeba18c0
sha512: bb8d35cc2b17025446ca8d483c4edd8d8ab3af57fd545c677c1f4ca97ac792c3f392a04c1b1993dd106279bcf467ea46439188faa6df95a287280ea36c8937ae
ssdeep: 12288:1pttfnWhO76Odns6JTPUxFFMDstuLafuYxSLFyL4jwdEYewexZ0oPWK9V5+1G2v:1LBWhS6OqgU7GDlLaWISXwrwT04VwRB
type: PE32 executable (console) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Web Archive Copyright 2014
InternalName: Windows Web Archive
FileVersion: 1.0.0.0
CompanyName: Windows Web Archive
LegalTrademarks:
Comments: Modified by an unpaid evaluation copy of Resource Tuner 2 (www.heaventools.com)
ProductName: Windows Web Archive
ProductVersion: 1.0.0.0
FileDescription: Windows Archive 2014
OriginalFilename:
Translation: 0x0000 0x04e3

PHP/Qhost.R also known as:

DrWebTrojan.Hosts.33304
Qihoo-360Win32/Trojan.Qhost.HwsBr1oA
CylanceUnsafe
VIPRETrojan.SpamThru
SangforTrojan.PHP.Qhost.j
K7AntiVirusTrojan ( 004affef1 )
K7GWTrojan ( 004affef1 )
Cybereasonmalicious.0342c6
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.PHP.Qhost.j
AlibabaTrojan:PHP/Qhost.bf3cc42a
NANO-AntivirusTrojan.Win32.Symmi.dindni
AegisLabTrojan.PHP.Qhost.4!c
RisingTrojan.Qhost!8.1B0 (CLOUD)
TACHYONTrojan/W32.Qhost.1609728
ComodoMalware@#2wegu37lus1t4
F-SecureTrojan.TR/Symmi.662528
TrendMicroTROJ_SPNR.3AK014
McAfee-GW-EditionBehavesLike.Win32.Dropper.jc
WebrootW32.Trojan.Spamthru
AviraTR/Symmi.662528
Antiy-AVLTrojan[Ransom]/Win32.Blocker
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmTrojan.PHP.Qhost.j
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Agent.C498054
McAfeeArtemis!A62E8DEB5ABE
MAXmalware (ai score=99)
VBA32Trojan.PHP.Qhost
MalwarebytesMalware.Heuristic.1003
PandaTrj/Genetic.gen
ESET-NOD32PHP/Qhost.R
TrendMicro-HouseCallTROJ_SPNR.3AK014
TencentPhp.Trojan.Qhost.Lknm
YandexTrojan.Symmi!U5h1IcKH6RQ
IkarusTrojan.PHP.Qhost
FortinetPHP/Qhost.R!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove PHP/Qhost.R?

PHP/Qhost.R removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment