Malware

PWS:Win32/QQpass!pz (file analysis)

Malware Removal

The PWS:Win32/QQpass!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/QQpass!pz virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine PWS:Win32/QQpass!pz?


File Info:

name: 079B48D4FFC44C75DECB.mlw
path: /opt/CAPEv2/storage/binaries/588727522a4b666f252d1e0f13b657ee538e5e4a0281085500ad8742c2d57231
crc32: F5BB3B6B
md5: 079b48d4ffc44c75decb4e62f857eb90
sha1: 7fb68b8776276c05ca1918b9d682b4568114aeac
sha256: 588727522a4b666f252d1e0f13b657ee538e5e4a0281085500ad8742c2d57231
sha512: 59c4722a0d23fc9907d6a99ba85efaa0d45c2c6a5b6d544c3c5dce54e602fe64b157be70c6ca2ffe0066391f8a74dd0fbb248eb475131b87199d5728f977e942
ssdeep: 12288:jka9ADsjMNzMKsQ5/p3q2BQaGxhVIxOoNSix:jF9YtbsedhG7VIxrSc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T117254B10B7CAC0B3CE87917D41EED75DC62796891B2228D3E3980F4F9EA07E25B75186
sha3_384: e0eefe4e49855171da0db1dac3a01d5bd025ac7fe22cac63923f5b78569352f33e89dbb7dbd8860ed49a31b918df8dec
ep_bytes: e8e6c10000e916feffff558bec515153
timestamp: 2008-11-06 01:22:36

Version Info:

0: [No Data]

PWS:Win32/QQpass!pz also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.284036
SkyhighBehavesLike.Win32.Infected.fh
McAfeeGenericRXBN-GJ!079B48D4FFC4
MalwarebytesMalware.AI.4102379072
VIPREGen:Variant.Zusy.284036
SangforTrojan.Win32.Save.a
Cybereasonmalicious.776276
VirITTrojan.Win32.Generic.LJC
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 99)
ClamAVWin.Malware.Swisyn-9968222-0
BitDefenderGen:Variant.Zusy.284036
NANO-AntivirusTrojan.Win32.Swisyn.brkakp
AvastWin32:TrojanX-gen [Trj]
RisingTrojan.Generic@AI.95 (RDMK:w8QE5sY2PQioFTc03Fq0dA)
TACHYONTrojan/W32.Agent.1028096.DG
EmsisoftGen:Variant.Zusy.284036 (B)
F-SecureHeuristic.HEUR/AGEN.1317886
DrWebTrojan.PWS.Spy.17230
ZillyaTrojan.Swisyn.Win32.30290
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Zusy.284036
JiangminTrojan/Swisyn.tjc
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1317886
ArcabitTrojan.Zusy.D45584
MicrosoftPWS:Win32/QQpass!pz
GoogleDetected
AhnLab-V3Trojan/Win32.Swisyn.C168873
MAXmalware (ai score=80)
Cylanceunsafe
PandaTrj/Genetic.gen
TencentMalware.Win32.Gencirc.10b33570
YandexTrojan.GenAsa!vQtlmKtB+kw
IkarusTrojan.Win32.Swisyn
FortinetW32/Generic.AC.4B0D!tr
BitDefenderThetaGen:NN.ZexaF.36680.!qW@aaeLOmmi
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove PWS:Win32/QQpass!pz?

PWS:Win32/QQpass!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment