Trojan

Trojan.Win32.Hotkeychick.qd removal tips

Malware Removal

The Trojan.Win32.Hotkeychick.qd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Hotkeychick.qd virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Sniffs keystrokes
  • Installs an hook procedure to monitor for mouse events
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings

How to determine Trojan.Win32.Hotkeychick.qd?


File Info:

name: 932B06E08E8E7FD7341F.mlw
path: /opt/CAPEv2/storage/binaries/93f411c1ea45801376d037ead020bbbe1c4d7cbebfe00d5c94922a635d01977d
crc32: 3DB44158
md5: 932b06e08e8e7fd7341f72e8fa264fe9
sha1: 045aae4e161be11b10e968e821b60da9c5374fd4
sha256: 93f411c1ea45801376d037ead020bbbe1c4d7cbebfe00d5c94922a635d01977d
sha512: 4305fe31467dda5cea4e7a42b029abb587e8b7eb78f9a57692ddf901ff950df64d18c64866263b22338355aaf3b8fe769f7601d7a33123d985d73a4902c3f0cb
ssdeep: 12288:rm4dSMnbmWoh7jpaj6SaDBFI7S106ONuVQJyI:r3BnbmWohXP5DB110RkTI
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T164A4239BF7414830CBEA87B994037E09E4674C59D6AB060BE0493CDB76B1B791CB1A36
sha3_384: 7da3e632ffc5388ddd54873fc9f6e858ab01d86d3fa053e5b7fae925975bdccad967c18d67f557d2ff0e2235a2bf408d
ep_bytes: 57565351524150488d05de0a0000488b
timestamp: 2021-08-29 00:00:17

Version Info:

FileDescription:
FileVersion: 1.1.33.10
InternalName:
LegalCopyright:
OriginalFilename:
ProductName:
ProductVersion: 1.1.33.10
Translation: 0x0409 0x04b0

Trojan.Win32.Hotkeychick.qd also known as:

MicroWorld-eScanTrojan.GenericKDZ.80085
FireEyeTrojan.GenericKDZ.80085
ALYacTrojan.GenericKDZ.80085
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Hotkeychick.49cedee6
K7GWRiskware ( 0040eff71 )
SymantecTrojan.Gen.MBT
TrendMicro-HouseCallTROJ_GEN.R011C0WKS21
Paloaltogeneric.ml
KasperskyTrojan.Win32.Hotkeychick.qd
BitDefenderTrojan.GenericKDZ.80085
AvastWin64:Malware-gen
TencentWin32.Trojan.Hotkeychick.Hqlf
Ad-AwareTrojan.GenericKDZ.80085
EmsisoftTrojan.GenericKDZ.80085 (B)
TrendMicroTROJ_GEN.R011C0WKS21
McAfee-GW-EditionBehavesLike.Win64.Generic.gc
SophosMal/Generic-S
GridinsoftRansom.Win64.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ViRobotTrojan.Win32.Z.Agent.491008.EO
GDataTrojan.GenericKDZ.80085
AhnLab-V3Trojan/Win.Generic.C4804860
McAfeeArtemis!932B06E08E8E
MAXmalware (ai score=89)
VBA32Trojan.Hotkeychick
APEXMalicious
MaxSecureTrojan.Malware.300983.susgen
FortinetMalicious_Behavior.SB
AVGWin64:Malware-gen
PandaTrj/CI.A

How to remove Trojan.Win32.Hotkeychick.qd?

Trojan.Win32.Hotkeychick.qd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment