Malware

PWS:Win32/QQPass.GP information

Malware Removal

The PWS:Win32/QQPass.GP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/QQPass.GP virus can do?

  • Attempts to connect to a dead IP:Port (4 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

ui.ptlogin2.qq.com
ocsp.dcocsp.cn
crl3.digicert.com
crl4.digicert.com
ssl.ptlogin2.qq.com
ocsp.digicert.cn
i3.tietuku.com
crl.digicert.cn

How to determine PWS:Win32/QQPass.GP?


File Info:

crc32: 441BA891
md5: b64f285b643e89c8d683a3853e5aedf1
name: B64F285B643E89C8D683A3853E5AEDF1.mlw
sha1: 54fba8765c3d3673bf7864b854b988144c5fcc1a
sha256: dcdc26ad1c58642da42c30e878b50edef7e1704c337b430eedd968c8a171d732
sha512: 7d88612ca9ee35fd228cec9b11654da456536337b09617f8937dae8605db6284694182e25f8e2b7fd85ae054d51251dc51343306972557c1c7c7f64b38c40e71
ssdeep: 6144:IXdaAfyvRwWoe2XlFSFb3bzpYpYFRQnyHWPBsxA:IXdaAqvRwWoe2XjSVvUYuyHWPBsxA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

PWS:Win32/QQPass.GP also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.48404
FireEyeGeneric.mg.b64f285b643e89c8
CAT-QuickHealTrojan.Qqpass.S3
ALYacGen:Variant.Razy.48404
MalwarebytesQQpass.Trojan.Stealer.DDS
ZillyaTrojan.QQPass.Win32.24534
AegisLabTrojan.Win32.QQPass.tpT3
SangforMalware
K7AntiVirusPassword-Stealer ( 0055e3dc1 )
BitDefenderGen:Variant.Razy.48404
K7GWPassword-Stealer ( 0055e3dc1 )
Cybereasonmalicious.b643e8
BitDefenderThetaGen:NN.ZexaF.34804.vmX@aeUzgae
CyrenW32/S-fe4d7b20!Eldorado
SymantecML.Attribute.HighConfidence
TotalDefenseWin32/Oflwr.A!crypt
BaiduWin32.Trojan-PSW.QQPass.ag
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Malware.Razy-6783523-0
KasperskyTrojan-PSW.Win32.QQPass.comr
NANO-AntivirusTrojan.Win32.QQPass.erawav
RisingTrojan.Kryptik!1.B3E8 (CLASSIC)
Ad-AwareGen:Variant.Razy.48404
EmsisoftGen:Variant.Razy.48404 (B)
ComodoTrojWare.Win32.QQPass.SAS@6w3nhd
F-SecureTrojan.TR/Crypt.XPACK.Gen3
DrWebTrojan.DownLoader12.47537
VIPRETrojan.Win32.Generic!BT
TrendMicroHT_QQPASS_FE25023C.UVPM
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
SophosML/PE-A + Mal/Emogen-P
SentinelOneStatic AI – Malicious PE – Spyware
JiangminTrojan/PSW.QQPass.qxe
AviraTR/Crypt.XPACK.Gen3
MAXmalware (ai score=86)
Antiy-AVLTrojan[PSW]/Win32.QQPass
MicrosoftPWS:Win32/QQPass.GP
ArcabitTrojan.Razy.DBD14
ZoneAlarmTrojan-PSW.Win32.QQPass.comr
GDataWin32.Trojan.Agent.WP
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C881765
Acronissuspicious
McAfeePWS-FCCD!B64F285B643E
VBA32BScope.Trojan.StartPage
CylanceUnsafe
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/PSW.QQPass.OVL
TrendMicro-HouseCallHT_QQPASS_FE25023C.UVPM
TencentMalware.Win32.Gencirc.10b08024
YandexTrojan.PWS.QQPass!C2RbOn8D8XE
IkarusTrojan-PSW.Win32.QQPass
eGambitUnsafe.AI_Score_97%
FortinetW32/GameHack.AX!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.PSW.41b

How to remove PWS:Win32/QQPass.GP?

PWS:Win32/QQPass.GP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment