Trojan

Trojan-Banker.Win32.Qbot.aagk removal instruction

Malware Removal

The Trojan-Banker.Win32.Qbot.aagk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Qbot.aagk virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.Qbot.aagk?


File Info:

crc32: 442E2E02
md5: 94f6bcd1c6b35a1c5d55dd2dbe7211da
name: 94F6BCD1C6B35A1C5D55DD2DBE7211DA.mlw
sha1: 4d6359c3e61f8d54863d183d38ddc548c2a8702b
sha256: 9237e5cae5f698d5ad9f6c61af8bd866e599abb05f5bc49474d98e269a29a588
sha512: 832cfab9ee1f813f2a9a2fa3afae32646a00c10c71930cd034efa2c07d588facb9d782deba930376a499f2e76f1177a4d3a39bd2ca8bbdc37586e092c72ef8b0
ssdeep: 24576:Mm4KIe7WgCBxOQyvlHxhXjqpdwWow1Rht956wCLVAWRCySnAZWX:14GQ9yvlHCdwSZT56wCL1bSn3
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.Qbot.aagk also known as:

MicroWorld-eScanTrojan.GenericKD.36367671
Qihoo-360Win32/Backdoor.QakBot.HgkASPUA
McAfeeArtemis!94F6BCD1C6B3
AegisLabTrojan.Win32.Qbot.7!c
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderTrojan.GenericKD.36367671
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
CyrenW32/Trojan.GUWW-4247
SymantecTrojan.Gen.MBT
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.Qbot.aagk
AlibabaTrojan:Win32/BankerX.48453ad0
RisingTrojan.Qbot!8.8A3 (CLOUD)
Ad-AwareTrojan.GenericKD.36367671
EmsisoftMalCert.A (A)
F-SecureTrojan.TR/Crypt.XPACK.Gen2
DrWebBackDoor.Qbot.589
TrendMicroTROJ_FRS.0NA103BJ21
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.94f6bcd1c6b35a1c
SophosMal/Generic-S
IkarusTrojan.Crypt
GDataWin32.Trojan.Agent.QDP5UD
WebrootW32.Trojan.Qakbot
AviraTR/Crypt.XPACK.Gen2
GridinsoftTrojan.Heur!.012100A0
ArcabitTrojan.Generic.D22AED37
ViRobotTrojan.Win32.Z.Wacatac.1380848
ZoneAlarmTrojan-Banker.Win32.Qbot.aagk
MicrosoftTrojan:Win32/Ymacco.AA92
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Qakbot.C4340884
ALYacTrojan.GenericKD.36367671
MAXmalware (ai score=88)
VBA32BScope.TrojanPSW.Coins
CylanceUnsafe
PandaTrj/CI.A
ESET-NOD32Win32/Qbot.CV
TrendMicro-HouseCallTROJ_FRS.0NA103BJ21
eGambitUnsafe.AI_Score_86%
FortinetW32/Qbot.AAGK!tr
AVGWin32:DangerousSig [Trj]
AvastWin32:DangerousSig [Trj]

How to remove Trojan-Banker.Win32.Qbot.aagk?

Trojan-Banker.Win32.Qbot.aagk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment