Categories: Trojan

What is “Trojan:Win32/Qbot.BX!MTB”?

The Trojan:Win32/Qbot.BX!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Qbot.BX!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Qbot.BX!MTB?


File Info:

crc32: 2320A4ECmd5: 16f4c0c84542a754939c19a43c47b79aname: 55555.pngsha1: 009ec481325b22c364791d1a1a24909b2d1b7b6fsha256: a5afbb1aa4f69920db5d7adff67323f8dce0d4d4cc673181d9e05b131a1050f1sha512: 612319bbbcaf898951851cad26406025421c9f916385107c1d1f51aa6a470e38bc059c157c840df75e037933e12326ca372c4991678e0dd7d7bcd355d1309aacssdeep: 6144:6bJlWua+qXOAHLj8fC/bJVWR8h7DzmzAEN:6bfVaCmVW8hrOAtype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.InternalName: Trustedikstaller.exeFileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)CompanyName: Microsoft CorporationProductName: Microsoftxae Windowsxae Operating SystemProductVersion: 6.1.7601.17514FileDescription: Windows Modules ikstallerOriginalFilename: Trustedikstaller.exeTranslation: 0x0409 0x04b0

Trojan:Win32/Qbot.BX!MTB also known as:

MicroWorld-eScan Trojan.Agent.ERFL
FireEye Generic.mg.16f4c0c84542a754
Qihoo-360 HEUR/QVM20.1.5EBD.Malware.Gen
McAfee W32/PinkSbot-GS!16F4C0C84542
ALYac Trojan.Agent.ERFL
Cylance Unsafe
BitDefender Trojan.Agent.ERFL
Cybereason malicious.1325b2
Invincea heuristic
BitDefenderTheta Gen:NN.ZexaF.34110.Km0@a0yQ4soi
Symantec Packed.Generic.459
ESET-NOD32 a variant of Win32/Kryptik.HDMT
APEX Malicious
Avast Win32:BankerX-gen [Trj]
GData Trojan.Agent.ERFL
Kaspersky Trojan.Win32.Zenpak.acgx
Endgame malicious (high confidence)
Sophos Troj/Qbot-FS
Comodo TrojWare.Win32.Spy.Agent.DA@8rxbw1
F-Secure Trojan.TR/Crypt.Agent.hvqpq
McAfee-GW-Edition BehavesLike.Win32.Expiro.hm
Emsisoft Trojan.Agent.ERFL (B)
Avira TR/Crypt.Agent.hvqpq
Antiy-AVL Trojan/Win32.Wacatac
Arcabit Trojan.Agent.ERFL
ZoneAlarm Trojan.Win32.Zenpak.acgx
Microsoft Trojan:Win32/Qbot.BX!MTB
MAX malware (ai score=80)
Ad-Aware Trojan.Agent.ERFL
Malwarebytes Trojan.Qbot
Panda Trj/GdSda.A
Rising Trojan.Kryptik!8.8 (C64:YzY0Ou6+AHP8rPy1)
SentinelOne DFI – Malicious PE
Fortinet W32/Kryptik.HDMT!tr
AVG Win32:BankerX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (D)

How to remove Trojan:Win32/Qbot.BX!MTB?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Malware.AI.2972915474 malicious file

The Malware.AI.2972915474 is considered dangerous by lots of security experts. When this infection is active,…

17 mins ago

Win32/Autoit.OPN information

The Win32/Autoit.OPN is considered dangerous by lots of security experts. When this infection is active,…

21 mins ago

Malware.AI.3788326785 removal

The Malware.AI.3788326785 is considered dangerous by lots of security experts. When this infection is active,…

37 mins ago

What is “Trojan.Generic.35619263”?

The Trojan.Generic.35619263 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Generic.Dacic.1A7FA519.A.F34D6DE8 removal instruction

The Generic.Dacic.1A7FA519.A.F34D6DE8 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Should I remove “Babar.143901”?

The Babar.143901 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago