Trojan

Trojan.MSIL.Qhost removal

Malware Removal

The Trojan.MSIL.Qhost is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MSIL.Qhost virus can do?

  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Trojan.MSIL.Qhost?


File Info:

name: 2DA91D3B61A22B91D0B3.mlw
path: /opt/CAPEv2/storage/binaries/58b09bc00c65d2fb88cd9372b230518fa370d7e136873cc415755217bdfb1524
crc32: 095BAB84
md5: 2da91d3b61a22b91d0b3b1a8b9f929c9
sha1: e12544300e6c59b4d0a88b9b3fc329cffeffcf8a
sha256: 58b09bc00c65d2fb88cd9372b230518fa370d7e136873cc415755217bdfb1524
sha512: 7d65ed85f7c576ac4c73b219f26b50b84a3c5f0fb0b1274fb24e189dce5aa481357c61bf162ec109725ba55fefaa242d364014557080a291109e4580f6f58d10
ssdeep: 49152:x1wrD2RR3/MMY7hl9plkgu7eSRY1wIyu4Mn1UvdbINTCM3iLxCgXttl1w5yS1w:/wrSRRW7/1kgu7swI9EbmTCkiL02dw5c
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T100B52315B7E18E11DC5A3AF4E4B84289067E7F524573A209367C392A5F722A7CF0638F
sha3_384: a834992c50d9a21554c5a82498f8ee25825b0ddc589e404ae67ce29ec97b4fc084224f9abb86373139e8e1cc90cc9ec1
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-11-20 23:59:12

Version Info:

Translation: 0x0000 0x04b0
Comments: Official Artemis Uplauncher
CompanyName: Artemis
FileDescription: Artemis Uplauncher
FileVersion: 1.0.1
InternalName: Uplauncher.exe
LegalCopyright: Copyright © 2021 Artemis - Tous droits réservés
LegalTrademarks: Artemis
OriginalFilename: Uplauncher.exe
ProductName: Artemis Uplauncher
ProductVersion: 1.0.1
Assembly Version: 1.0.1.0

Trojan.MSIL.Qhost also known as:

LionicTrojan.MSIL.Qhost.4!c
MicroWorld-eScanTrojan.GenericKD.47456788
FireEyeTrojan.GenericKD.47456788
ALYacTrojan.GenericKD.47456788
SymantecML.Attribute.HighConfidence
KasperskyHEUR:Trojan.MSIL.Qhost.gen
BitDefenderTrojan.GenericKD.47456788
AvastWin32:Malware-gen
TencentMsil.Trojan.Qhost.Huqb
Ad-AwareTrojan.GenericKD.47456788
SophosMal/Generic-S
F-SecureTrojan.TR/Qhost.ubmew
TrendMicroTROJ_GEN.R002C0WKN21
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.47456788 (B)
IkarusTrojan-Downloader.Agent
GDataTrojan.GenericKD.47456788
JiangminTrojan.MSIL.aliwq
AviraTR/Qhost.ubmew
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.RL_Generic.C4317415
McAfeeArtemis!2DA91D3B61A2
MAXmalware (ai score=80)
MalwarebytesMachineLearning/Anomalous.100%
TrendMicro-HouseCallTROJ_GEN.R002C0WKN21
SentinelOneStatic AI – Suspicious PE
FortinetPossibleThreat
AVGWin32:Malware-gen
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.MSIL.Qhost?

Trojan.MSIL.Qhost removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment