Trojan

Trojan-Banker.Win32.Qbot.wdi removal guide

Malware Removal

The Trojan-Banker.Win32.Qbot.wdi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Qbot.wdi virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Mimics the system’s user agent string for its own requests
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

www.ip-adress.com

How to determine Trojan-Banker.Win32.Qbot.wdi?


File Info:

crc32: E629B7AB
md5: fba887d2cbf3951fb1f607a17f3b1a15
name: tmpbqje0qwv
sha1: 9475bdd1ee9b666fbce5bcdfb0a8edbf15a8f046
sha256: 9a57219e7d116c7c42da973896a77d248eb22db62e03c19cc859186fee327e55
sha512: f2c38f722bdb9aa73ba61955217c3bedc4b5f038b5a29381f82c6bdfd0fb47910ca94aac35230c16204ec0b222a6e0ba1acb479f233352015beed713303ba36b
ssdeep: 12288:X2UML/axdZPF/evu3xbKSq8H7SNQTLBR32Yrm20:X2UM7A6u3MwH+NQTVR32Ya20
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: RDPClip
FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7601.17514
FileDescription: RDP Clip Monitor
OriginalFilename: RDPClip.exe
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.Qbot.wdi also known as:

BkavW32.AIDetectVM.malwareA
DrWebTrojan.QakBot.10
MicroWorld-eScanTrojan.GenericKD.43337883
FireEyeGeneric.mg.fba887d2cbf3951f
McAfeeW32/PinkSbot-GW!FBA887D2CBF3
ALYacTrojan.GenericKD.43337883
CylanceUnsafe
SangforMalware
BitDefenderTrojan.GenericKD.43337883
K7GWTrojan ( 00568c4c1 )
Cybereasonmalicious.1ee9b6
BitDefenderThetaGen:NN.ZexaF.34128.bP1@aujN8Gbi
GDataWin32.Backdoor.QakBot.KK11C6
KasperskyTrojan-Banker.Win32.Qbot.wdi
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.43337883 (B)
Invinceaheuristic
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.moderate.ml.score
SophosTroj/Qbot-FS
MAXmalware (ai score=85)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
ArcabitTrojan.Generic.D295489B
ZoneAlarmTrojan-Banker.Win32.Qbot.wdi
MicrosoftTrojan:Win32/Qakbot.SD!MTB
CynetMalicious (score: 100)
Acronissuspicious
VBA32Malware-Cryptor.Limpopo
Ad-AwareTrojan.GenericKD.43337883
MalwarebytesTrojan.Qbot
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HEBQ
RisingTrojan.Kryptik!1.C745 (RDMK:cmRtazoF45UoQ4G0hsaytArz/UOi)
SentinelOneDFI – Malicious PE
eGambitPE.Heur.InvalidSig
FortinetW32/Cridex.VHO!tr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM19.1.F012.Malware.Gen

How to remove Trojan-Banker.Win32.Qbot.wdi?

Trojan-Banker.Win32.Qbot.wdi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment