Trojan

Trojan:Win32/Qakbot!pz removal instruction

Malware Removal

The Trojan:Win32/Qakbot!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Qakbot!pz virus can do?

  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Qakbot!pz?


File Info:

name: 770453C5D3ED689A451D.mlw
path: /opt/CAPEv2/storage/binaries/f2f80e624a3bcaec31ecb73a8d75715189b7baa73176fa773a986ff80c19976d
crc32: 8FE78E9F
md5: 770453c5d3ed689a451d55e947764742
sha1: 1971af01230229e08c15ff0810dcefa3e9a29ff4
sha256: f2f80e624a3bcaec31ecb73a8d75715189b7baa73176fa773a986ff80c19976d
sha512: 1f8d5b9907e35801536316b5297df25c1e314f873b3115b62a22a57fdff850dcb035c685ddc6a06ef8c0071cbdf4a0310db624eeb0acbb1131c03aed28ee8f1f
ssdeep: 6144:Ve+9dH7mdgjTTi96d7B9+stcTNWY76POE9F/nvaGYuidCHhhF0K:VeMdhjCYOTNWY76z/vaGL
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T15184BEC0CE9648B0DD8E68BD41FEE927053A1E2D0316C6E389943E05FDB27D766B528D
sha3_384: 816bfd8b7beab61396e4ad38e027383326d7daeed0d6bd692c6f34dc1b764cc60dabdb99a0ae25c111f526029a34fc73
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2014-05-22 09:24:40

Version Info:

ProductName: WebP library
FileDescription: ImageMagick Studio library and utility programs
OriginalFilename: webp
InternalName: ImageMagick Studio
FileVersion: 0.4.0 (30 December 2013)
ProductVersion: 0.4.0 (30 December 2013)
CompanyName: Google Inc.
LegalCopyright: Copyright (c) 2010, Google Inc. All rights reserved.
Comments: https://code.google.com/p/webp
Translation: 0x0409 0x04b0

Trojan:Win32/Qakbot!pz also known as:

BkavW32.Common.3A51201E
LionicTrojan.Win32.Qbot.11!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Tedy.311034
FireEyeGen:Variant.Tedy.311034
SkyhighBehavesLike.Win32.PinkSbot.fc
ALYacTrojan.Agent.QakBot
Cylanceunsafe
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojanBanker:Win32/Kryptik.849acf45
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Tedy.D4BEFA
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Kryptik.HSXP
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Banker.Win32.Qbot.ahgo
BitDefenderGen:Variant.Tedy.311034
NANO-AntivirusTrojan.Win32.Qbot.jvcxyr
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.1188acd4
EmsisoftGen:Variant.Tedy.311034 (B)
F-SecureHeuristic.HEUR/AGEN.1364478
VIPREGen:Variant.Tedy.311034
TrendMicroTROJ_GEN.R002C0DGQ23
SophosMal/Generic-S
IkarusBackdoor.QBot
WebrootW32.Trojan.Qakbot
GoogleDetected
AviraHEUR/AGEN.1364478
Antiy-AVLTrojan[Banker]/Win32.Qbot
XcitiumMalware@#13ynms2n0muqj
MicrosoftTrojan:Win32/Qakbot!pz
ZoneAlarmTrojan-Banker.Win32.Qbot.ahgo
GDataGen:Variant.Tedy.311034
VaristW32/Qbot.ON.gen!Eldorado
AhnLab-V3Malware/Win.Generic.C5392278
McAfeeRDN/seheq
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0DGQ23
RisingBackdoor.Qakbot!1.E3C8 (CLASSIC)
MaxSecureTrojan.Malware.203060479.susgen
FortinetW32/Qbot.DM!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Qakbot!pz?

Trojan:Win32/Qakbot!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment