Trojan

Trojan-Banker.Win32.Qbot.xyw malicious file

Malware Removal

The Trojan-Banker.Win32.Qbot.xyw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Qbot.xyw virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.Qbot.xyw?


File Info:

crc32: B2F39A44
md5: 2d90f39b9629e3e0f933f7b20a87f192
name: upload_file
sha1: 07eb52aacfd4c7a1f9599118c9fe47561d45efdd
sha256: 96f3ce81be9c325cbcf7a4d6ac1d9f853786f438e14c7ac2efab1f3a9f92e17e
sha512: e951c11413c2ea53b548ea2dafa578d97533d78d26e12ed0eeb95836a3c8a3b81b098d71a5360ab380908d85223a1d6aed31eda2e6ad019e161052829a8ac3cc
ssdeep: 6144:hy5RbM/fsmoLYZj9qWCOWhcXF8rqeEaQDAV:hCRQOY7qWCdh68rqeEaQDC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Headlight Software, Inc. All rights reserved.
InternalName: AdminPrivSetting.exe
FileVersion: 1.0.6.5
CompanyName: Headlight Software, Inc.
ProductName: (Shared by Headlight Software Products)
ProductVersion: 1.0.6.5
FileDescription: Change Settings that need Admin Privileges
OriginalFilename: AdminPrivSetting.exe
Translation: 0x0409 0x04e4

Trojan-Banker.Win32.Qbot.xyw also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.776355
FireEyeGeneric.mg.2d90f39b9629e3e0
McAfeeW32/PinkSbot-HG!2D90F39B9629
CylanceUnsafe
K7AntiVirusTrojan ( 00571ebf1 )
BitDefenderGen:Variant.Razy.776355
K7GWTrojan ( 00571ebf1 )
InvinceaML/PE-A
CyrenW32/Kryptik.CIH.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Banker.Win32.Qbot.xyw
NANO-AntivirusVirus.Win32.Gen.ccmw
Ad-AwareGen:Variant.Razy.776355
McAfee-GW-EditionW32/PinkSbot-HG!2D90F39B9629
EmsisoftGen:Variant.Razy.776355 (B)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.AR!Cert
GridinsoftTrojan.Win32.Kryptik.oa!s1
ArcabitTrojan.Razy.DBD8A3
SUPERAntiSpywareTrojan.Agent/Generic
ZoneAlarmTrojan-Banker.Win32.Qbot.xyw
GDataGen:Variant.Razy.776355
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZexaF.34590.pm1@a4D5mdgi
ALYacGen:Variant.Razy.776355
MAXmalware (ai score=84)
VBA32BScope.Trojan.Wacatac
MalwarebytesBackdoor.Qbot
ESET-NOD32a variant of Win32/GenKryptik.EVFR
RisingDropper.Generic!8.35E (TFE:2:OiOHnZAitmO)
SentinelOneDFI – Malicious PE
eGambitPE.Heur.InvalidSig
FortinetW32/Kryptik.HHAF!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM19.1.F96B.Malware.Gen

How to remove Trojan-Banker.Win32.Qbot.xyw?

Trojan-Banker.Win32.Qbot.xyw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment