Trojan

Trojan:Win32/Qbot.RTH!MTB information

Malware Removal

The Trojan:Win32/Qbot.RTH!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Qbot.RTH!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Qbot.RTH!MTB?


File Info:

crc32: 34E5A9DB
md5: ef135e02cd07e94c493061950ea99a3e
name: EF135E02CD07E94C493061950EA99A3E.mlw
sha1: 1b0cbec8bc066ebe12ab6a66e8e8901c2024bf03
sha256: 2866a252b6007fe9487d85b87ed23f6dddaf2f4f8ccc82328212985bfc6dd5d5
sha512: 3654bffbf3dcecd629fda6e5c1fb1b5d41c814ed321633d8beba964341009c7be47bbccbac137e79f6a694b3dc05a18f529b5f7e0305899760a1d5e4a3c94ec3
ssdeep: 6144:zEg5nOUIs9bdyXs14wKLw/LDZn1TUPgflDnAKzNYx4kCn4In8/v9Mm2nlI2L5D3:A+OUIs9bW04wMoAPcJ7zNiIvmAEjQ0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Qbot.RTH!MTB also known as:

K7AntiVirusTrojan ( 0057af701 )
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Injector.8c8374d3
K7GWTrojan ( 0057af701 )
Cybereasonmalicious.8bc066
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EPDB
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.Win32.Scar.gen
BitDefenderTrojan.GenericKD.36981140
MicroWorld-eScanTrojan.GenericKD.36981140
Ad-AwareTrojan.GenericKD.36981140
TrendMicroTROJ_GEN.R002C0DER21
McAfee-GW-EditionBehavesLike.Win32.Worm.hh
FireEyeGeneric.mg.ef135e02cd07e94c
EmsisoftTrojan.GenericKD.36981140 (B)
SentinelOneStatic AI – Malicious PE
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Qbot.RTH!MTB
AegisLabTrojan.Win32.Scar.4!c
GDataTrojan.GenericKD.36981140
McAfeeRDN/Generic.grp
MAXmalware (ai score=89)
VBA32BScope.Trojan.Scar
MalwarebytesMalware.AI.2718723711
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DER21
RisingTrojan.Injector!1.D632 (CLOUD)
IkarusTrojan.Win32.Injector
FortinetW32/Injector.EPDB!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan:Win32/Qbot.RTH!MTB?

Trojan:Win32/Qbot.RTH!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment