Trojan

Trojan:Win32/Obfuscator.QB!MTB information

Malware Removal

The Trojan:Win32/Obfuscator.QB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Obfuscator.QB!MTB virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Obfuscator.QB!MTB?


File Info:

crc32: 1E1324B4
md5: 0aaeecf18177e9beb320bcccd5e1da13
name: 0AAEECF18177E9BEB320BCCCD5E1DA13.mlw
sha1: 84ec66cb76d491070039a584de658506e10b9934
sha256: 3795a2228558a1b136746ea70125bc53cf05e2a6ce078d39667af4e3adee3a02
sha512: 675d3cd66aed97ceb68b19fa5b28c7f943669a11f6154eb3d5e52d879179c161c07b9e8487eb5e298c5fee9b7806e50ba3133b7459d88fc419268ec0a4bd1b6f
ssdeep: 6144:BpqR+KB/8d6atokDR9Lf2QT5ruKk4HathGrO:Bp8n/8saOkrDhm4HathGq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2002-2016 RealVNC Ltd.
InternalName: vncpasswd
FileVersion: 6.0.1 (r23971)
CompanyName: RealVNC Ltd
LegalTrademarks: VNC is a registered trademark of RealVNC Ltd in the U.S. and in other countries.
ProductName: VNCxae
ProductVersion: 6.0.1 (r23971)
ProgramName: VNCxae Password Utility
FileDescription: VNCxae Password Utility
OriginalFilename: vncpasswd.exe
Translation: 0x0809 0x04b0

Trojan:Win32/Obfuscator.QB!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Dridex.705
MicroWorld-eScanTrojan.Mint.Zamg.O
FireEyeGeneric.mg.0aaeecf18177e9be
ALYacTrojan.Mint.Zamg.O
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005683eb1 )
BitDefenderTrojan.Mint.Zamg.O
K7GWTrojan ( 005683eb1 )
Cybereasonmalicious.b76d49
BitDefenderThetaGen:NN.ZexaF.34634.Mm1@aaQtE1oi
CyrenW32/Trojan.DZU.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DangerousSig [Trj]
KasperskyHEUR:Trojan-Downloader.Win32.Cridex.pef
NANO-AntivirusTrojan.Win32.Dridex.hlsxoq
Ad-AwareTrojan.Mint.Zamg.O
SophosMal/EncPk-APV
InvinceaMal/EncPk-APV
EmsisoftAdware.Generic (A)
IkarusTrojan.Win32.Pluf
JiangminTrojanDownloader.Cridex.sm
AviraHEUR/AGEN.1135020
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Obfuscator.QB!MTB
ArcabitTrojan.Mint.Zamg.O
ZoneAlarmHEUR:Trojan-Downloader.Win32.Cridex.pef
GDataTrojan.Mint.Zamg.O
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Dridex.R340673
McAfeeGenericRXAA-AA!0AAEECF18177
VBA32BScope.Trojan.Jorik
MalwarebytesTrojan.MalPack.DGI
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HDZX
RisingTrojan.Kryptik!1.C778 (CLASSIC)
SentinelOneStatic AI – Malicious PE
eGambitPE.Heur.InvalidSig
AVGWin32:DangerousSig [Trj]
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360HEUR/QVM20.1.44A7.Malware.Gen

How to remove Trojan:Win32/Obfuscator.QB!MTB?

Trojan:Win32/Obfuscator.QB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment