Trojan

Trojan-Banker.Win32.Qbot.zau (file analysis)

Malware Removal

The Trojan-Banker.Win32.Qbot.zau is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Qbot.zau virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process created a hidden window
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file

Related domains:

edgedl.me.gvt1.com

How to determine Trojan-Banker.Win32.Qbot.zau?


File Info:

crc32: A8010816
md5: e82409ea272b7e25bde1f71a695c2a14
name: E82409EA272B7E25BDE1F71A695C2A14.mlw
sha1: b121ff9962d5d249af4cd7019e562f7430ff8d6a
sha256: 9bd1c080d357debc532639edb67f010aaa440d6122cbd2414212fd0b1d1fe61f
sha512: e010ffc21e7b070df37cbb4733bfa5503cc6711fde09e2af4cb9cfc071cc9806bf8a2bfefc405f1566004c16efd5a627caac54c91111baf326c3c72aa520d351
ssdeep: 6144:QnQU+LqGvHr0nNK11G9DMEeZa8POyKmLUyaViFwRuEz:3FrkNK11G9AEtMxQyOi6dz
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.Qbot.zau also known as:

Elasticmalicious (high confidence)
DrWebBackDoor.Qbot.554
ClamAVWin.Packed.Qbot-9802444-0
CAT-QuickHealTrojan.WacatacPMF.S17478005
ALYacTrojan.Agent.EZUU
CylanceUnsafe
ZillyaTrojan.Qbot.Win32.12493
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanBanker:Win32/Qakbot.94dab06a
K7GWBackdoor ( 00573a2f1 )
K7AntiVirusBackdoor ( 00573a2f1 )
CyrenW32/Trojan.TKFK-5799
SymantecTrojan.Maltrec.TS
ESET-NOD32Win32/Qbot.CU
APEXMalicious
AvastWin32:DangerousSig [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Banker.Win32.Qbot.zau
BitDefenderTrojan.Agent.EZUU
NANO-AntivirusTrojan.Win32.Qbot.iddayn
MicroWorld-eScanTrojan.Agent.EZUU
Ad-AwareTrojan.Agent.EZUU
SophosML/PE-A + Mal/EncPk-APW
F-SecureTrojan.TR/AD.Qbot.lnibt
BitDefenderThetaGen:NN.ZedlaF.34700.vm5@ai2YYFjG
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PL420
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
FireEyeGeneric.mg.e82409ea272b7e25
EmsisoftMalCert.A (A)
JiangminTrojan.Banker.Qbot.vo
AviraTR/AD.Qbot.lnibt
eGambitUnsafe.AI_Score_64%
Antiy-AVLTrojan/Win32.Qbot
MicrosoftTrojan:Win32/Qakbot.V!cert
GridinsoftRansom.Win32.Wacatac.oa!s1
ArcabitTrojan.Agent.EZUU
ZoneAlarmTrojan-Banker.Win32.Qbot.zau
GDataTrojan.Agent.EZUU
AhnLab-V3Trojan/Win32.Qakbot.C4250802
Acronissuspicious
McAfeeGenericRXNB-KM!E82409EA272B
MAXmalware (ai score=88)
VBA32Malware-Cryptor.General.3
MalwarebytesTrojan.Cutwail
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PL420
RisingTrojan.Qbot!8.8A3 (TFE:5:0xawzPgvv7O)
IkarusTrojan.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Qbot.CU!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM39.1.B49F.Malware.Gen

How to remove Trojan-Banker.Win32.Qbot.zau?

Trojan-Banker.Win32.Qbot.zau removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment