Trojan

Trojan-PSW.Win32.Qbot.aem (file analysis)

Malware Removal

The Trojan-PSW.Win32.Qbot.aem is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Qbot.aem virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Creates a copy of itself

Related domains:

zipansion.com
usfinf.net

How to determine Trojan-PSW.Win32.Qbot.aem?


File Info:

crc32: 72F0BA30
md5: 44efb905fcf8c371afac20f6a2938dbf
name: 44EFB905FCF8C371AFAC20F6A2938DBF.mlw
sha1: d558af80fe3c946feea15fc3f003538455f7ad12
sha256: 5fac6ea5496ec14ad1c70c54f9b18c82db34f74f20c5c1ca32b7b303246798e0
sha512: af71ae2b49806a5f495cc5e43aef877fc8aeaaedfd68123d6bc2ca3f2603196cc312a8b6a2359d71b2dd7a815e2ea00f6b8fd87dcf478404dc764606d005aced
ssdeep: 49152:ph+kxBi3UwYD15sHluRwKKK9T0jt9m326tMA:t7ikw415sM1P26
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan-PSW.Win32.Qbot.aem also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0056f44b1 )
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.381404
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
K7GWTrojan ( 0056f44b1 )
Cybereasonmalicious.5fcf8c
CyrenW32/Kryptik.CYM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GKAM
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Packed.Razy-9820160-0
KasperskyTrojan-PSW.Win32.Qbot.aem
BitDefenderGen:Variant.Razy.381404
MicroWorld-eScanGen:Variant.Razy.381404
Ad-AwareGen:Variant.Razy.381404
SophosTroj/Agent-BGPN
BitDefenderThetaAI:Packer.76E8294D1E
McAfee-GW-EditionBehavesLike.Win32.VirRansom.tc
FireEyeGeneric.mg.44efb905fcf8c371
EmsisoftGen:Variant.Razy.381404 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Khalesi.bdqa
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34A812D
MicrosoftTrojan:Win32/AgentCrypt.SM!MTB
ZoneAlarmTrojan-PSW.Win32.Qbot.aem
GDataWin32.Trojan.PSE.1RK2E61
AhnLab-V3Malware/Win.Generic.R373678
McAfeeGenericRXAA-AA!44EFB905FCF8
MAXmalware (ai score=80)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.MalPack
RisingTrojan.Kryptik!1.D12D (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Khalesi.VHO!tr
AVGWin32:Trojan-gen

How to remove Trojan-PSW.Win32.Qbot.aem?

Trojan-PSW.Win32.Qbot.aem removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment