Trojan

Trojan:Win32/Qbot.SO!MTB removal

Malware Removal

The Trojan:Win32/Qbot.SO!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Qbot.SO!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Qbot.SO!MTB?


File Info:

crc32: 42F1F46A
md5: ad4b33a6dfd72c332e85e9eb2cf8be14
name: AD4B33A6DFD72C332E85E9EB2CF8BE14.mlw
sha1: b5da6667013913a236efa7d56aba7aa715dee1f4
sha256: 3cb9cf69179d6edbb2082a012863067f59b09eab446cbe7f69baf5eafa88c230
sha512: 2bfd00eae3a46f3c9ec617f52ae3b9bec86137f919ee0907ae63518f0185c357ec670d2725530334be479b5f5789c7f36ae8538873ca50904205b32a3ad022bd
ssdeep: 6144:nJ0Fa940xzcpre663fgwc85C6OZ2xWmw+Cu:nJ0FO40xw3rwc85Cz8xWB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Qbot.SO!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.338720
FireEyeGeneric.mg.ad4b33a6dfd72c33
ALYacGen:Variant.Zusy.338720
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0057328f1 )
BitDefenderGen:Variant.Zusy.338720
K7GWTrojan ( 0057328f1 )
Cybereasonmalicious.701391
TrendMicroTROJ_GEN.R06EC0DKG20
BitDefenderThetaGen:NN.ZexaF.34634.qmW@aC1eo8f
CyrenW32/Qbot.AK.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Packed.Qbot-9791227-0
KasperskyUDS:DangerousObject.Multi.Generic
NANO-AntivirusVirus.Win32.Gen.ccmw
RisingTrojan.Kryptik!1.CE73 (CLASSIC)
Ad-AwareGen:Variant.Zusy.338720
SophosMal/EncPk-APV
DrWebTrojan.DownLoader35.29790
InvinceaML/PE-A + Mal/EncPk-APV
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftGen:Variant.Zusy.338720 (B)
IkarusWin32.Outbreak
JiangminTrojanDownloader.Agent.fxzo
MaxSecureTrojan.Malware.1207211.susgen
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=80)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qbot.SO!MTB
ArcabitTrojan.Zusy.D52B20
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Zusy.338720
CynetMalicious (score: 100)
Acronissuspicious
McAfeeGenericRXAA-AA!AD4B33A6DFD7
VBA32BScope.Trojan.Wacatac
MalwarebytesBackdoor.Agent
ESET-NOD32a variant of Win32/GenKryptik.EVZE
TrendMicro-HouseCallTROJ_GEN.R06EC0DKG20
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Lupus.E56C!tr
AVGWin32:BankerX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM20.1.4DA3.Malware.Gen

How to remove Trojan:Win32/Qbot.SO!MTB?

Trojan:Win32/Qbot.SO!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment