Trojan

About “Trojan:Win32/Qbot.TO!MTB” infection

Malware Removal

The Trojan:Win32/Qbot.TO!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Qbot.TO!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by registry key
  • Anomalous binary characteristics

How to determine Trojan:Win32/Qbot.TO!MTB?


File Info:

crc32: 76F1E624
md5: e644e9923925f1413ec930e0a214e763
name: E644E9923925F1413EC930E0A214E763.mlw
sha1: 317cce677abb5a7244fa5330c90a134cc0675a10
sha256: c8faf0e5ce250dcd52bf7f1e1a8dbce24e0ad807d7085c075151c4ccfcccec64
sha512: 4fd6f4f0de17988b0c2d9044d8ff53f977eb7bbc7d666e3e6ae207510d79fcc56eaa6a8eebce33bb65540e4da69114f8dacfbd50d73405635204a00b15cbbfcc
ssdeep: 6144:1AjQoypxPmZbdrFO5Z7Y2VYFIJdpuCNu6p+meK:OjQOpkZ08YF6pv+5K
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileDescription: Remote Quota Manager
FileVersion: 1. 8.0.1800
CompanyName: Lovelysoft
Translation: 0x0409 0x04e4

Trojan:Win32/Qbot.TO!MTB also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
ClamAVWin.Malware.Bunitu-6922426-0
CAT-QuickHealRansom.Locky.ZZ4
ALYacTrojan.GenericKDZ.40555
AegisLabHacktool.Win32.Krap.lKMc
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0051806a1 )
BitDefenderTrojan.GenericKDZ.40555
K7GWTrojan ( 0051806a1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D9E6B
CyrenW32/Kryptik.CUI.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.FXAT
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Bunitu.ali1000105
NANO-AntivirusTrojan.Win32.Yakes.etbgzx
MicroWorld-eScanTrojan.GenericKDZ.40555
TencentMalware.Win32.Gencirc.1169bea1
Ad-AwareTrojan.GenericKDZ.40555
EmsisoftTrojan.GenericKDZ.40555 (B)
ComodoTrojWare.Win32.Bunitu.FEZT@79gsl9
F-SecureHeuristic.HEUR/AGEN.1117378
DrWebTrojan.Siggen8.38513
ZillyaTrojan.Yakes.Win32.65878
TrendMicroRansom_HPCERBER.SMALY5B
McAfee-GW-EditionBehavesLike.Win32.Ransomware.jh
FireEyeGeneric.mg.e644e9923925f141
SophosMal/Generic-R + Mal/Cerber-AL
IkarusTrojan-Proxy.Win32.Bunitu
AviraHEUR/AGEN.1117378
eGambitUnsafe.AI_Score_99%
MAXmalware (ai score=99)
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojan:Win32/Qbot.TO!MTB
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKDZ.40555
AhnLab-V3Win-Trojan/RansomCrypt.Gen
McAfeeRansomware-GGI!E644E9923925
VBA32BScope.TrojanProxy.Bunitu
MalwarebytesQbot.Backdoor.Stealer.DDS
PandaTrj/CI.A
TrendMicro-HouseCallRansom_HPCERBER.SMALY5B
RisingTrojan.Kryptik!1.AD43 (CLOUD)
YandexTrojan.GenAsa!qi2+OYkHHr0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Dridex.IZC!tr
BitDefenderThetaGen:NN.ZexaF.34608.Rq1@aS5VChnk
AVGWin32:Malware-gen
Cybereasonmalicious.23925f
AvastWin32:Malware-gen
Qihoo-360Win32/Trojan.Generic.HxQBWJcA

How to remove Trojan:Win32/Qbot.TO!MTB?

Trojan:Win32/Qbot.TO!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment