Trojan

Trojan-PSW.Win32.QQPass.7003 removal instruction

Malware Removal

The Trojan-PSW.Win32.QQPass.7003 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.QQPass.7003 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan-PSW.Win32.QQPass.7003?


File Info:

name: EAD341400E19F71EDE7B.mlw
path: /opt/CAPEv2/storage/binaries/8fa6b6301331406d6312fb1c771954d9adacfb6cdfa535acd342d8615501c041
crc32: E7603A99
md5: ead341400e19f71ede7b975a20c50092
sha1: 430a872e6e51121a3659feb8f8a348b8e4fdf60e
sha256: 8fa6b6301331406d6312fb1c771954d9adacfb6cdfa535acd342d8615501c041
sha512: b158e3aa8835d7354cbb9bdda0d929a51923968875320b160208517684e4fea4aded183e295bde3a660efcc42c3f59ccee3f64bf7a1855f541bfa3907923ef3d
ssdeep: 6144:krXCeJuDx3OJda+ONYnHyRKXAbZR/fjtxsYVUz8Z8XK+a8zeFj4dVVRV:krXCPx1pY0bZZfjxvcpzV/b
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DED48D26F2D08837D2732A3C9C5B97649C2AFEA12D3A15452BF83D4C4F397817926397
sha3_384: 29cb32c91cf95aaa5ef78e752a8ce39ee49d2124a5fd94e6c4e1b676cee4732ed6c3d5ef53d9b3a356135d9f636543ed
ep_bytes: 558bec83c4f033c08945f0b8884f4500
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan-PSW.Win32.QQPass.7003 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.ead341400e19f71e
SkyhighBehavesLike.Win32.PWSLegMir.jm
McAfeePWS-QQPass
Cylanceunsafe
VIPREGen:Trojan.ShellHook.MuY@aCMN3Fob
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
AlibabaWorm:Win32/Fasong.485
K7GWTrojan ( 7000000f1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.ShellHook.EAC042
BaiduWin32.Trojan-PSW.OLGames.bm
VirITTrojan.Win32.Generic.ESM
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Fasong.J
APEXMalicious
ClamAVWin.Malware.Lmir-7595062-0
KasperskyTrojan-PSW.Win32.QQPass.7003
BitDefenderGen:Trojan.ShellHook.MuY@aCMN3Fob
NANO-AntivirusTrojan.Win32.QQPass.focoup
MicroWorld-eScanGen:Trojan.ShellHook.MuY@aCMN3Fob
TencentTrojan.Win32.Scar.16000123
SophosTroj/PWS-BUY
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.PWS.Qqpass
ZillyaTrojan.QQPass.Win32.13564
EmsisoftGen:Trojan.ShellHook.MuY@aCMN3Fob (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/PaPa.13
GoogleDetected
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan[PSW]/Win32.QQPass
Kingsoftmalware.kb.a.1000
XcitiumPacked.Win32.MUPX.Gen@24tbus
MicrosoftPWS:Win32/QQpass.7003
ZoneAlarmTrojan-PSW.Win32.QQPass.7003
GDataGen:Trojan.ShellHook.MuY@aCMN3Fob
VaristW32/Legendmir.IZFX-3783
AhnLab-V3Trojan/Win.QQPass.R547680
VBA32TrojanPSW.QQpass
ALYacGen:Trojan.ShellHook.MuY@aCMN3Fob
MAXmalware (ai score=81)
DeepInstinctMALICIOUS
MalwarebytesFasong.Worm.Dropper.DDS
RisingWorm.Fasong!1.D14C (CLASSIC)
YandexTrojan.GenAsa!twKpA3v7Te4
IkarusTrojan-GameThief.Win32.Lmir
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Delf.FT!tr
BitDefenderThetaAI:Packer.C91BF4A221
Cybereasonmalicious.e6e511
PandaTrj/Genetic.gen

How to remove Trojan-PSW.Win32.QQPass.7003?

Trojan-PSW.Win32.QQPass.7003 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment