Trojan

Should I remove “Trojan.Win32.Qshell.kzt”?

Malware Removal

The Trojan.Win32.Qshell.kzt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Qshell.kzt virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known windows from debuggers and forensic tools
  • Created a process from a suspicious location
  • Attempts to disable Windows Defender
  • Attempts to modify Windows Defender using PowerShell
  • Attempts to execute suspicious powershell command arguments

How to determine Trojan.Win32.Qshell.kzt?


File Info:

name: CBA2DB833CCEB38685FD.mlw
path: /opt/CAPEv2/storage/binaries/70b5b60abcd160d442efc0203d14f3b85117edead74c7f35c105a5a7dfe21478
crc32: 562674C6
md5: cba2db833cceb38685fdec9cf2070ec0
sha1: b6d93ef0f53cb88399e1e4f76e99a98939ec7a40
sha256: 70b5b60abcd160d442efc0203d14f3b85117edead74c7f35c105a5a7dfe21478
sha512: a0bed27bb733c1d97a86fd8f98b0712f873baab13a68cec3eb3d112e38fde1d9907ac769fb76a44394687ad2f806852e16146e6ac4f8739925e3b31dd27573a5
ssdeep: 196608:Jt/a8/Y13gfSoaaoVSy5ZrNyMCVgtppIPTmKHsidYwAM0:Jt/a8/YaKlwy5ZJ5CeIKKMeYwl0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11C6633B6876A20CFD1A998F03C9D74792A93C8C631CA5D43D5D33E446132D27F8962BE
sha3_384: 53bd83d670185a9ad591d253b6240a108648ebe6b2826c802714c383495d149723089b23fa41fffb3b4cefa9228323e5
ep_bytes: 81ecd40200005356576a205f33db6801
timestamp: 2020-08-01 02:44:18

Version Info:

0: [No Data]

Trojan.Win32.Qshell.kzt also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
FireEyeGeneric.mg.cba2db833cceb386
CAT-QuickHealTrojan.Sabsik
ALYacGen:Variant.Jaik.47957
BitDefenderGen:Variant.Jaik.47957
CyrenW32/Trojan.UKBR-7070
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
ClamAVWin.Malware.Barys-9859499-0
KasperskyTrojan.Win32.Qshell.kzt
AlibabaTrojan:Win32/DelfInject.ali2000015
NANO-AntivirusRiskware.Win32.PassView.hmklhx
TencentWin32.Trojan.Multiple.Tbig
EmsisoftGen:Variant.Jaik.47957 (B)
ComodoMalware@#1plllgwcbxxww
BitDefenderThetaGen:NN.ZexaF.34182.hu0@aGDuBSeO
TrendMicroTROJ_GEN.R002C0WLO21
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosMal/Generic-L
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1144141
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.34F5E5E
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Jaik.47957
CynetMalicious (score: 100)
VBA32BScope.Trojan.Zapchast
MalwarebytesSpyware.PasswordStealer
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0WLO21
RisingDropper.Agent/NSIS!1.D805 (CLASSIC:bWQ1OoPii0PGfaw5kpgfTqPxBi0)
IkarusTrojan-Downloader.Win32.Agent
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
Cybereasonmalicious.33cceb
AvastWin32:Malware-gen

How to remove Trojan.Win32.Qshell.kzt?

Trojan.Win32.Qshell.kzt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment