Trojan

Trojan-Banker.Win32.Qbot.oeb malicious file

Malware Removal

The Trojan-Banker.Win32.Qbot.oeb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Qbot.oeb virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality

How to determine Trojan-Banker.Win32.Qbot.oeb?


File Info:

crc32: CF782A5F
md5: 7ce93e540de95b4153b953b9070d6f36
name: vvvv.exe
sha1: 2909fe83cc2754daa8223c40e0f9d2cc8291ee4f
sha256: ffb5d8c941c81435ec6998e1edb72a0c3224158a87451975ecd201c11bdb4b85
sha512: 814a003b80a107582721be7a21903f31104b9d0499a4a233508c28601ac21c94c52c87c63f7411798aef838cb0b7cb7a59b208b1289fa1bbfed96af6330b0fe2
ssdeep: 12288:pli+DBCYyRl9iIgMw6T+etB7T2B5ZTzFxOUgx:9yGTxOUc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002-2008 Mark Russinovich and Bryce Cogswell
InternalName: Ercihhdsewee Rtrssiet
FileVersion: 0.03
CompanyName: Sysinternals - www.sysinternals.com
ProductName: Ercihhdsewee rtrssiet
ProductVersion: 0.03
FileDescription: Autostart program viewer
OriginalFilename: ercihhds.exe
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.Qbot.oeb also known as:

DrWebTrojan.PWS.Spy.21405
MicroWorld-eScanTrojan.GenericKD.33050639
FireEyeGeneric.mg.7ce93e540de95b41
ALYacTrojan.Agent.Occamy.A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Malicious.4!c
K7AntiVirusTrojan ( 0055fb991 )
BitDefenderTrojan.GenericKD.33050639
K7GWTrojan ( 0055fb991 )
Cybereasonmalicious.3cc275
TrendMicroTROJ_GEN.R011C0WB820
BitDefenderThetaGen:NN.ZexaF.34090.yq0@aC1TPYci
APEXMalicious
AvastWin32:BankerX-gen [Trj]
GDataTrojan.GenericKD.33050639
KasperskyTrojan-Banker.Win32.Qbot.oeb
AlibabaTrojanBanker:Win32/Kryptik.fbec2688
TencentWin32.Trojan-banker.Qbot.Ammr
Ad-AwareTrojan.GenericKD.33050639
SophosTroj/Qbot-FA
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.PUPXAA.fc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.33050639 (B)
IkarusTrojan.Win32.Crypt
CyrenW32/Trojan.UOCX-5857
MAXmalware (ai score=82)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F8500F
ZoneAlarmTrojan-Banker.Win32.Qbot.oeb
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
McAfeeRDN/Generic.grp
MalwarebytesBackdoor.Qbot
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HAXG
TrendMicro-HouseCallTROJ_GEN.R011C0WB820
RisingTrojan.Generic@ML.93 (RDMK:CSZmxMizRxbjfeasUS9AiA)
SentinelOneDFI – Malicious PE
FortinetW32/Kryptik.HAXG!tr
WebrootW32.Trojan.Gen
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (W)
Qihoo-360Generic/HEUR/QVM10.2.142F.Malware.Gen

How to remove Trojan-Banker.Win32.Qbot.oeb?

Trojan-Banker.Win32.Qbot.oeb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment