Trojan

Trojan.Qakbot removal

Malware Removal

The Trojan.Qakbot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Qakbot virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

www.ip-adress.com

How to determine Trojan.Qakbot?


File Info:

crc32: C5F69775
md5: 78a53e535e229dfeaf3c57f0c83a47c0
name: upload_file
sha1: 0ef53e8d25d6f5cdf1cfd36663de20b1e615d700
sha256: 3a971cb00b359b0a9a86157d6e19e2710e7f42098eb4fdd3f8d46f5333cdbf45
sha512: 8bfd42d7ce022fc7ea152425cc40b45504212d7694f45660855ef4c97c7e1036c6997581cc01aa7778b52547802afac3744f103508b404b0ade6c724ba5e1b9e
ssdeep: 12288:gyB8tzikyTxNxUNxNxAixNxgxNxXptLCXgtM:gb7yl1M
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Qakbot also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.69395
FireEyeGeneric.mg.78a53e535e229dfe
CAT-QuickHealTrojan.Qakbot
McAfeeW32/PinkSbot-GZ!78A53E535E22
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0056c68d1 )
BitDefenderTrojan.GenericKDZ.69395
K7GWTrojan ( 0056c68d1 )
Cybereasonmalicious.d25d6f
Invinceaheuristic
F-ProtW32/Qbot.Q.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DangerousSig [Trj]
AlibabaTrojan:Win32/Qakbot.93723956
RisingTrojan.Kryptik!1.CA76 (CLASSIC)
Ad-AwareTrojan.GenericKDZ.69395
F-SecureTrojan.TR/Crypt.EPACK.Gen2
DrWebBackDoor.Qbot.536
TrendMicroTROJ_GEN.R002C0DHD20
SophosMal/EncPk-APV
SentinelOneDFI – Suspicious PE
CyrenW32/Qbot.Q.gen!Eldorado
AviraTR/Crypt.EPACK.Gen2
FortinetW32/GenKryptik.EQEC!tr
Antiy-AVLGrayWare/Win32.Kryptik.ehls
ArcabitTrojan.Generic.D10F13
MicrosoftTrojan:Win32/Qakbot.VD!Cert
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Qakbot.R347713
VBA32Trojan.Inject
ALYacTrojan.GenericKDZ.69395
MAXmalware (ai score=86)
MalwarebytesBackdoor.Qbot
PandaTrj/Agent.OOW
ESET-NOD32a variant of Win32/Kryptik.HFMH
TrendMicro-HouseCallBackdoor.Win32.QAKBOT.SMF
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_87%
GDataWin32.Trojan.PSE.F2XJCJ
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.9ad

How to remove Trojan.Qakbot?

Trojan.Qakbot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment