Trojan

What is “Trojan:Win32/Qbot.BX!MTB”?

Malware Removal

The Trojan:Win32/Qbot.BX!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Qbot.BX!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Qbot.BX!MTB?


File Info:

crc32: 2320A4EC
md5: 16f4c0c84542a754939c19a43c47b79a
name: 55555.png
sha1: 009ec481325b22c364791d1a1a24909b2d1b7b6f
sha256: a5afbb1aa4f69920db5d7adff67323f8dce0d4d4cc673181d9e05b131a1050f1
sha512: 612319bbbcaf898951851cad26406025421c9f916385107c1d1f51aa6a470e38bc059c157c840df75e037933e12326ca372c4991678e0dd7d7bcd355d1309aac
ssdeep: 6144:6bJlWua+qXOAHLj8fC/bJVWR8h7DzmzAEN:6bfVaCmVW8hrOA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Trustedikstaller.exe
FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7601.17514
FileDescription: Windows Modules ikstaller
OriginalFilename: Trustedikstaller.exe
Translation: 0x0409 0x04b0

Trojan:Win32/Qbot.BX!MTB also known as:

MicroWorld-eScanTrojan.Agent.ERFL
FireEyeGeneric.mg.16f4c0c84542a754
Qihoo-360HEUR/QVM20.1.5EBD.Malware.Gen
McAfeeW32/PinkSbot-GS!16F4C0C84542
ALYacTrojan.Agent.ERFL
CylanceUnsafe
BitDefenderTrojan.Agent.ERFL
Cybereasonmalicious.1325b2
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34110.Km0@a0yQ4soi
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.HDMT
APEXMalicious
AvastWin32:BankerX-gen [Trj]
GDataTrojan.Agent.ERFL
KasperskyTrojan.Win32.Zenpak.acgx
Endgamemalicious (high confidence)
SophosTroj/Qbot-FS
ComodoTrojWare.Win32.Spy.Agent.DA@8rxbw1
F-SecureTrojan.TR/Crypt.Agent.hvqpq
McAfee-GW-EditionBehavesLike.Win32.Expiro.hm
EmsisoftTrojan.Agent.ERFL (B)
AviraTR/Crypt.Agent.hvqpq
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Agent.ERFL
ZoneAlarmTrojan.Win32.Zenpak.acgx
MicrosoftTrojan:Win32/Qbot.BX!MTB
MAXmalware (ai score=80)
Ad-AwareTrojan.Agent.ERFL
MalwarebytesTrojan.Qbot
PandaTrj/GdSda.A
RisingTrojan.Kryptik!8.8 (C64:YzY0Ou6+AHP8rPy1)
SentinelOneDFI – Malicious PE
FortinetW32/Kryptik.HDMT!tr
AVGWin32:BankerX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Qbot.BX!MTB?

Trojan:Win32/Qbot.BX!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment