Trojan

About “Trojan:Win32/Pwsteal.Q!rfn” infection

Malware Removal

The Trojan:Win32/Pwsteal.Q!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Pwsteal.Q!rfn virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs

How to determine Trojan:Win32/Pwsteal.Q!rfn?


File Info:

crc32: E92EBCBF
md5: 202385f29c36895949d165210a9f5da5
name: goziwecry.exe
sha1: f176f2947de987b92cd5cdffdf45d408bd8352e2
sha256: d1b2f65b28a57ce6df70de26603f57740e32676e3f245e063a4c00b5fa2a38bd
sha512: 02c54c0228f40caefbd8a14ad51fd601704eddf2547b5627ac65021a5ec2d69e241e350e2acb19db6b623b21d2fa22ff88067321fffb0784d4201cc79ffccef5
ssdeep: 6144:vHxIDVuVUejFVtOND+XseABxopTUzncazmUa1Z9:mF0Ah+XseABMT+cma1Z
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2013
InternalName: EMailSpliter
FileVersion: 1, 0, 0, 1
CompanyName: by suruiqiang (Y!M: suruiqiang)
ProductName: EMailSpliter
ProductVersion: 1, 0, 0, 1
FileDescription: EMailSpliter
OriginalFilename: EMailSpliter.EXE
Translation: 0x0804 0x04b0

Trojan:Win32/Pwsteal.Q!rfn also known as:

DrWebTrojan.DownLoader33.7086
MicroWorld-eScanTrojan.GenericKD.42683833
FireEyeGeneric.mg.202385f29c368959
Qihoo-360Generic/HEUR/QVM03.0.7B3F.Malware.Gen
McAfeePacked-FWY!202385F29C36
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0056081c1 )
BitDefenderTrojan.GenericKD.42683833
K7GWTrojan ( 0056081c1 )
Cybereasonmalicious.47de98
TrendMicroTROJ_GEN.R067C0PBQ20
BitDefenderThetaGen:NN.ZemsilF.34090.Hm0@aiqnxGsj
SymantecTrojan Horse
APEXMalicious
AvastWin32:KeyloggerX-gen [Trj]
GDataTrojan.GenericKD.42683833
KasperskyHEUR:Backdoor.MSIL.Androm.gen
AlibabaTrojan:Win32/csharp.ali2000008
NANO-AntivirusTrojan.Win32.Androm.hcchcg
ViRobotTrojan.Win32.S.Infostealer.544768.C
AegisLabTrojan.MSIL.Androm.m!c
RisingTrojan.Lokibot!8.F1B5 (CLOUD)
Ad-AwareTrojan.GenericKD.42683833
SophosTroj/Fareit-JTP
ComodoMalware@#385sq4zpohhrf
F-SecureTrojan.TR/Kryptik.gyult
Invinceaheuristic
McAfee-GW-EditionPacked-FWY!202385F29C36
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.Crypt (A)
IkarusTrojan.MSIL.Inject
CyrenW32/Trojan.DDFL-5956
WebrootW32.Trojan.Gen
AviraTR/Kryptik.gyult
Antiy-AVLTrojan[Backdoor]/MSIL.Androm
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D28B4DB9
ZoneAlarmHEUR:Backdoor.MSIL.Androm.gen
MicrosoftTrojan:Win32/Pwsteal.Q!rfn
TACHYONTrojan-PWS/W32.DN-Lokibot.544768
AhnLab-V3Trojan/Win32.Agent.R284273
Acronissuspicious
ALYacSpyware.LokiBot
MAXmalware (ai score=100)
MalwarebytesSpyware.LokiBot
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/GenKryptik.EFBM
TrendMicro-HouseCallTROJ_GEN.R067C0PBQ20
TencentWin32.Backdoor.Fareit.Auto
FortinetMSIL/Kryptik.UQP!tr
AVGWin32:KeyloggerX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.73691364.susgen

How to remove Trojan:Win32/Pwsteal.Q!rfn?

Trojan:Win32/Pwsteal.Q!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment