Spy Trojan

What is “TrojanSpy:Win32/Qeds.A”?

Malware Removal

The TrojanSpy:Win32/Qeds.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Qeds.A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanSpy:Win32/Qeds.A?


File Info:

name: CC98DE9A88872F18C959.mlw
path: /opt/CAPEv2/storage/binaries/18a16975cdbce7638bc46f1260e942fd57418eaa06bcf6a9528ea6fee1acd066
crc32: 587B982A
md5: cc98de9a88872f18c959b2c727e5b710
sha1: e3801b8f709b8882f9e679c20fa314e8c7f52c67
sha256: 18a16975cdbce7638bc46f1260e942fd57418eaa06bcf6a9528ea6fee1acd066
sha512: 91dcd670ed3fd4c98605c787a8e83520c42587c4436a0115ee36aa27be1147798d7c27b057828a1d17a8197c5cb5c6dc328a997a24238223c83dfde6a769e5d1
ssdeep: 96:8hrwHHLvR73BKaXETnmzq1UjE+1VWozLy6XiRdlXFc3WTMZRJCLf/NPBhT:6rwlk/yO1cfzLgRdLc32MfWfFJhT
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1B5F17DC437C0568EF4F5D7750CAE016EF176BD818BD2261F938042FE2CA6521C69AAA1
sha3_384: 82d1c3cf46b2cf6471073bd66be587496767fb128e9a744d36b7fb25c569688d74d563fd1eaf2bb540f12105d7ec17ff
ep_bytes: b8f09c00105064ff3500000000648925
timestamp: 2004-02-01 21:15:06

Version Info:

Comments: 冯潇设计
CompanyName: 风云谷
FileDescription: 风云谷类支持库
FileVersion: 3.0
InternalName: 风云谷
LegalCopyright: 风云谷版权所有(C)2002-2004
LegalTrademarks:
OriginalFilename: FYP.dll
PrivateBuild:
ProductName: FVP
ProductVersion: 3.0
SpecialBuild:
Translation: 0x0804 0x04b0

TrojanSpy:Win32/Qeds.A also known as:

LionicTrojan.Win32.Agent.kZxJ
SkyhighBehavesLike.Win32.CoinMiner.zh
McAfeeArtemis!CC98DE9A8887
Cylanceunsafe
CrowdStrikewin/malicious_confidence_70% (D)
K7GWRiskware ( f15000051 )
K7AntiVirusRiskware ( f15000051 )
BitDefenderThetaGen:NN.ZedlaF.36680.aqSfaefzA6lb
VirITBackdoor.Win32.PowerSpider.OY
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/PSWTool.PasswordSpy.AA potentially unsafe
Kasperskynot-a-virus:PSWTool.Win32.Finder.a
NANO-AntivirusRiskware.Win32.Finder.hqke
AvastWin32:Trojano-AWE [Trj]
TencentMalware.Win32.Gencirc.13c1596a
DrWebBackDoor.PowerSpider.388
ZillyaTool.Finder.Win32.15
TrendMicroHKTL_FINDER.C
SophosTroj/Netsnake-I
IkarusTrojan-Spy.Agent
JiangminTrojanSpy.Qeds.a
WebrootTrojanSpy:Win32/Qeds.A
GoogleDetected
Kingsoftmalware.kb.a.967
XcitiumHeur.Packed.MultiPacked@1z141z3
MicrosoftTrojanSpy:Win32/Qeds.A
ZoneAlarmnot-a-virus:PSWTool.Win32.Finder.a
VBA32Backdoor.PowerSpider
PandaHackTool/Finder.A
TrendMicro-HouseCallHKTL_FINDER.C
RisingMalware.Qeds!8.EAF2 (CLOUD)
YandexTrojanSpy.Qeds!WGl0FpCEOJc
FortinetRiskware/Finder
AVGWin32:Trojano-AWE [Trj]
DeepInstinctMALICIOUS

How to remove TrojanSpy:Win32/Qeds.A?

TrojanSpy:Win32/Qeds.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment