Trojan

What is “Trojan-PSW.Win32.QQPass.mbpo”?

Malware Removal

The Trojan-PSW.Win32.QQPass.mbpo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.QQPass.mbpo virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan-PSW.Win32.QQPass.mbpo?


File Info:

name: 9E50DB4A729EA5D6C054.mlw
path: /opt/CAPEv2/storage/binaries/f4bbc1e8345410af394995a019ed72169dfa5101498661cbc12a29734b79a701
crc32: 867F2BBE
md5: 9e50db4a729ea5d6c0541f564c039d58
sha1: a495695aadaa64f593144d87e1c57d085d2b3bb7
sha256: f4bbc1e8345410af394995a019ed72169dfa5101498661cbc12a29734b79a701
sha512: d72c6e67e14c1a19b80650b19a15239d60cc2298bc012b64a0e69deffe6fd223dab2a45e90d0a08bac243fae0ae26caa6f109ebbdd16012437dd94ab91e8a918
ssdeep: 393216:yPyea1K/a96hgIiMLaRuRBgpm9J+qhjgAs:+a1J96gPRurgpVq1gAs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F8F63346B182D034CCA5027218A157BA4E26BD724BE5C0F3FBC5F13AEE727D2967164B
sha3_384: 83f7e0bc8915cece75177f2b3269f49beda12124c34f8e4ef7d71c38436fbe91f42631cc7fa068db4046c25b0074cb55
ep_bytes: e8a61d0000e989feffff8bff565733f6
timestamp: 2011-02-02 14:21:34

Version Info:

Comments: by iMortaluz
CompanyName: 7usb.tk
FileDescription: Update
FileVersion: 2.9.9.5
InternalName: sf_rt
LegalCopyright: Copyright = Right To Copy!
OriginalFilename: suf_launch.exe
ProductName: Windows 7 USB Drive Edition
ProductVersion: 2.9.9.5
Translation: 0x0409 0x0000

Trojan-PSW.Win32.QQPass.mbpo also known as:

BkavW32.Common.7AC573AE
LionicTrojan.Win32.QQPass.i!c
SkyhighArtemis
McAfeeArtemis!9E50DB4A729E
ZillyaTrojan.Generic.Win32.1855081
SangforInfostealer.Win32.QQPass.Vkgo
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojanPSW:Win32/QQPass.bd3d6ef2
K7GWRiskware ( 00584baa1 )
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win32.QQPass.mbpo
AvastWin32:Malware-gen
TencentWin32.Trojan-QQPass.QQRob.Mcnw
KingsoftWin32.Troj.Unknown.a
ZoneAlarmTrojan-PSW.Win32.QQPass.mbpo
Cylanceunsafe
RisingTrojan.Generic@AI.83 (RDML:jc2DH+nW7IKB+oBRR6kxiA)
AVGWin32:Malware-gen

How to remove Trojan-PSW.Win32.QQPass.mbpo?

Trojan-PSW.Win32.QQPass.mbpo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment