Trojan

How to remove “Trojan-Banker.Win32.Qbot.xcm”?

Malware Removal

The Trojan-Banker.Win32.Qbot.xcm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Qbot.xcm virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

www.ip-adress.com

How to determine Trojan-Banker.Win32.Qbot.xcm?


File Info:

crc32: CCCFB6C2
md5: fa6c8544582eb8d56f67d19aa4605e8f
name: upload_file
sha1: 76e3040264035380d8c433855a4c52aec410f3be
sha256: 8d599d914d05deb914de734363d6cedd29e097436d9ee21968bbcacc495b92c9
sha512: 6719e142194842261bcf34f9b0abb16a5fb1c05d64080d37c060d4be855ea9a677031e30b2fb86ab6bb767083a8a2dcb8aecf70426dfcfa062bfd6858638c726
ssdeep: 12288:6yP/ms6j2cyD9QoPfhLwVSZR0mji1AqTVc2xrW6aGrjlnxVQVR:6yP/mswQ3nhL57u1AUVcarWFGrpnDQVR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) Laplink Software, Inc. 2007
InternalName: LLUSBArrival.exe
FileVersion: 17.500.01700.0
CompanyName: Laplink Software, Inc.
Comments: Laplink Gold Component
ProductName: Laplink Gold
ProductVersion: 14.01.0017.00
FileDescription: Laplink USB Autoplay Handler
OriginalFilename: LLUSBArrival.exe
Translation: 0x0409 0x04e4

Trojan-Banker.Win32.Qbot.xcm also known as:

BkavW32.AIDetectVM.malware2
DrWebTrojan.Inject3.45578
MicroWorld-eScanTrojan.GenericKDZ.69164
FireEyeGeneric.mg.fa6c8544582eb8d5
ALYacTrojan.GenericKDZ.69164
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKDZ.69164
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.264035
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34152.Qy1@a4@@VEei
SymantecPacked.Generic.459
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKDZ.69164
KasperskyTrojan-Banker.Win32.Qbot.xcm
AlibabaTrojanBanker:Win32/Kryptik.00208d32
AegisLabTrojan.Win32.Qbot.7!c
Endgamemalicious (high confidence)
SophosMal/EncPk-APV
F-SecureTrojan.TR/Crypt.Agent.mpsbi
TrendMicroTROJ_GEN.R002C0OH120
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.69164 (B)
IkarusTrojan-Banker.QakBot
JiangminTrojan.Banker.Qbot.te
AviraTR/Crypt.Agent.mpsbi
Antiy-AVLTrojan[Banker]/Win32.Qbot
MicrosoftTrojan:Win32/Qakbot.VC!Cert
ArcabitTrojan.Generic.D10E2C
ZoneAlarmTrojan-Banker.Win32.Qbot.xcm
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Qakbot.R346679
McAfeePacked-GCB!FA6C8544582E
MAXmalware (ai score=88)
VBA32BScope.Trojan.Zenpak
MalwarebytesTrojan.Dropper
ESET-NOD32a variant of Win32/Kryptik.HFIE
TrendMicro-HouseCallTROJ_GEN.R002C0OH120
RisingTrojan.Kryptik!1.C9B1 (CLOUD)
SentinelOneDFI – Malicious PE
eGambitPE.Heur.InvalidSig
FortinetW32/GenKryptik.EOHS!tr
Ad-AwareTrojan.GenericKDZ.69164
AVGWin32:BankerX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.BO.463

How to remove Trojan-Banker.Win32.Qbot.xcm?

Trojan-Banker.Win32.Qbot.xcm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment