Trojan

About “Trojan:Win32/BitRat.QY!MTB” infection

Malware Removal

The Trojan:Win32/BitRat.QY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/BitRat.QY!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/BitRat.QY!MTB?


File Info:

crc32: 9FAE6E38
md5: cb6c87f8ea5d63a28244ad5b9ff3ce3b
name: CB6C87F8EA5D63A28244AD5B9FF3CE3B.mlw
sha1: 40524a066ef1649403759f295d952f135e9c4003
sha256: 14854d1ce96dcc9795941ec7248f8d2481d5649cdeecaccbfe840f259bc50bde
sha512: 5ca75a0a7c2ba7f42e21256b28021a18749c74418cc00b9395b6e58efa59e05824077ec9b1014af034befe4ce6d5618f66a1963167702d5975c8fd02a8bdb7ae
ssdeep: 6144:cQq2/PTw+lkdnLfcjH4GHXUqsYrwAk0I39ah3MA2BrCZY0:P3Twjn4T40eAk3Na9or0
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright:
FileVersion: $VERSION
CompanyName: OpenMS Developer Team
ProductName: OpenMS
ProductVersion: $VERSION
FileDescription:
CompanyWebsite: http://www.OpenMS.de
Translation: 0x0000 0x04e4

Trojan:Win32/BitRat.QY!MTB also known as:

K7AntiVirusTrojan ( 0057d20b1 )
DrWebTrojan.Siggen13.45692
CynetMalicious (score: 100)
ALYacTrojan.Agent.Hynamer
CylanceUnsafe
SangforSpyware.Win32.Noon.gen
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0057d20b1 )
CyrenW32/Ninjector.C.gen!Camelot
SymantecTrojan.Gen.2
ESET-NOD32multiple detections
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.Win32.Vobfus.gen
BitDefenderTrojan.GenericKD.36981836
MicroWorld-eScanTrojan.GenericKD.36981836
Ad-AwareTrojan.GenericKD.36981836
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
FireEyeTrojan.GenericKD.36981836
EmsisoftTrojan.GenericKD.46368909 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/AD.Swotter.qtrdj
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/BitRat.QY!MTB
AegisLabTrojan.Win32.Noon.l!c
GDataWin32.Trojan-Stealer.FormBook.YQWXLS
AhnLab-V3Infostealer/Win.Formbook.C4495888
McAfeeRDN/Noon
MAXmalware (ai score=81)
TrendMicro-HouseCallTROJ_GEN.F0D1C00ER21
IkarusWin32.Outbreak
FortinetW32/Kryptik.AKX!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan:Win32/BitRat.QY!MTB?

Trojan:Win32/BitRat.QY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment