Trojan

What is “Trojan:Win32/Qbot.PVC!MTB”?

Malware Removal

The Trojan:Win32/Qbot.PVC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Qbot.PVC!MTB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan:Win32/Qbot.PVC!MTB?


File Info:

crc32: 8785A2A9
md5: e007d00762561874c2fb89b5acb26b6b
name: E007D00762561874C2FB89B5ACB26B6B.mlw
sha1: aff57252a3ca854f39a3676a5676eacf62cbc363
sha256: f2c8edc668e9fe03d975b4e89ad3a8dbda4c3465c3dec667b9409541c79433b8
sha512: 822242f1e7a537795f1d09b7fa7e7a5bc4bcad315d36457cc5206cd340811ead1772ef6b91e22d7d02d9111bd37436a7a93c73c605158a49f7b72ad09a87170a
ssdeep: 6144:+wsjfhIZ77mLRMtvGUpRGcZ8yhHVh8f45mlazP61:FAhIZ77mL+pMxyVL8fePzP61
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: extractr.exe
FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7601.17514
FileDescription: Wimfltr v2 extractor
OriginalFilename: extractr.exe
Translation: 0x0409 0x04b0

Trojan:Win32/Qbot.PVC!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35952905
FireEyeGeneric.mg.e007d00762561874
Qihoo-360Generic/HEUR/QVM40.1.517B.Malware.Gen
ALYacTrojan.GenericKD.35952905
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/BankerX.3578ad76
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
ArcabitTrojan.Generic.D2249909
CyrenW32/Wacatac.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyHEUR:Trojan-Banker.Win32.RTM.vho
BitDefenderTrojan.GenericKD.35952905
Paloaltogeneric.ml
Ad-AwareTrojan.GenericKD.35952905
EmsisoftTrojan.GenericKD.35952905 (B)
DrWebTrojan.Inject4.6417
TrendMicroTROJ_GEN.R011C0RA521
McAfee-GW-EditionGenericRXNE-QJ!E007D0076256
SophosMal/Generic-R + Mal/EncPk-APV
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Banker.RTM.vp
Antiy-AVLGrayWare/Win32.Kryptik.ehls
GridinsoftRansom.Win32.Filecoder.sd!s1
MicrosoftTrojan:Win32/Qbot.PVC!MTB
AegisLabHacktool.Win32.Krap.lKMc
ZoneAlarmHEUR:Trojan-Banker.Win32.RTM.vho
GDataTrojan.GenericKD.35952905
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Reputation.C4286661
McAfeeGenericRXNE-QJ!E007D0076256
MAXmalware (ai score=89)
VBA32TrojanBanker.RTM
ESET-NOD32Win32/Qbot.CV
TrendMicro-HouseCallTROJ_GEN.R011C0RA521
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HDZK!tr
BitDefenderThetaGen:NN.ZedlaF.34742.qA8@aueMYUoi
AVGWin32:BankerX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Trojan:Win32/Qbot.PVC!MTB?

Trojan:Win32/Qbot.PVC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment