Trojan

Trojan:BAT/QHosts removal tips

Malware Removal

The Trojan:BAT/QHosts is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:BAT/QHosts virus can do?

  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • The sample wrote data to the system hosts file.

How to determine Trojan:BAT/QHosts?


File Info:

crc32: 3207B635
md5: 72ddf833fa206326e15c2c97679d323e
name: 72DDF833FA206326E15C2C97679D323E.mlw
sha1: ad148ff4b7f77831b469be8bb19d32d029c23b50
sha256: 387bcf2758752a65d0b3cef4bba95d5b1ef6e16e09e75a21e343ad2a407380c1
sha512: 66fd693751c90c10eb527b91a095af8464a59c5252d6455198cfe8289f1e94e2a062dc3841914b19aba93e152452c004d4c70dd8c7eda380b98b59ce841bf305
ssdeep: 768:b+euRG38y78h8g6EMRb9WXwiel3GyxEZSs:r2GMy78v6E0EXwvbU
type: PE32 executable (console) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright:
FileVersion: 1. 0. 0. 0
CompanyName: Anemeros
Comments:
ProductName:
ProductVersion: 1. 0. 0. 0
FileDescription:
Translation: 0x0000 0x04e4

Trojan:BAT/QHosts also known as:

BkavW32.Common.1A77D7C9
K7AntiVirusTrojan ( 004951bd1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Qhost
ALYacTrojan.Agent.BBQL
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:BAT/Qhost.1f3e8da0
K7GWTrojan ( 004951bd1 )
Cybereasonmalicious.3fa206
BaiduWin32.Trojan.Qhost.d
CyrenW32/Trojan.KKQP-3298
SymantecML.Attribute.HighConfidence
ESET-NOD32BAT/Qhost.NTH
ZonerTrojan.Win32.21900
APEXMalicious
AvastWin32:QHost-CGQ [Trj]
ClamAVWin.Trojan.Razy-9622928-0
KasperskyTrojan.BAT.Qhost.abp
BitDefenderTrojan.Agent.BBQL
NANO-AntivirusTrojan.Win32.Qhost.dgkfuh
SUPERAntiSpywareTrojan.Agent/Gen-Qhost
MicroWorld-eScanTrojan.Agent.BBQL
TencentMalware.Win32.Gencirc.10b3700b
Ad-AwareTrojan.Agent.BBQL
SophosMal/Generic-S + Mal/Generic-L
ComodoSuspicious@#cu88gzqz2csi
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_QHOST.HZL
McAfee-GW-EditionGeneric.ru
FireEyeGeneric.mg.72ddf833fa206326
EmsisoftTrojan.Agent.BBQL (B)
JiangminTrojan.BAT.Qhost.a
WebrootW32.Malware.Gen
AviraTR/Qhost.mju.53
MicrosoftTrojan:BAT/QHosts
ArcabitTrojan.Agent.BBQL
AegisLabTrojan.BAT.Qhost.tpSL
ZoneAlarmTrojan.BAT.Qhost.abp
GDataWin32.Trojan.Agent.M0UU9M
AhnLab-V3Trojan/Win32.Qhost.R77387
McAfeeGeneric.ru
MAXmalware (ai score=88)
MalwarebytesTrojan.Qhost
PandaTrj/Spambot.C
TrendMicro-HouseCallTROJ_QHOST.HZL
RisingTrojan.Win32.QHost.awv (CLOUD)
IkarusTrojan.Win32.Qhost
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/Qhost.ABP!tr
AVGWin32:QHost-CGQ [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Qhost.HwsBnmAA

How to remove Trojan:BAT/QHosts?

Trojan:BAT/QHosts removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment