Trojan

Trojan:Win32/QHosts.BF removal

Malware Removal

The Trojan:Win32/QHosts.BF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/QHosts.BF virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • The sample wrote data to the system hosts file.
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/QHosts.BF?


File Info:

name: E082B88DF640EE43A4D9.mlw
path: /opt/CAPEv2/storage/binaries/66c229ead49189d369d04c41bd28a045b2b48b73233cd874c18bcd15f476c535
crc32: 1AC825D7
md5: e082b88df640ee43a4d9ef63a3b0cd40
sha1: 57753829fd791eb29c48216710b65dd65f33da9c
sha256: 66c229ead49189d369d04c41bd28a045b2b48b73233cd874c18bcd15f476c535
sha512: 096debbbbdbb2fc8476883de041193254235e8eedc2377c4fbec801e06416d18e0ee41dea6a179a02696f0c8e905a57d4897236c3f89cc857a9bbaa59f10386d
ssdeep: 3072:+BAp5XhKpN4eOyVTGfhEClj8jTk+0hdWMQ11Gas:VbXE9OiTGfhEClq9bMc1ts
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E004F812A4418973C0010576CC079E96B4A72DD03E35B7B3BFB55AFBCE69C8A7B2C169
sha3_384: 1226045e3ccacd8e6927ae78902a5368530e032589162561b9e2dc2b91e1f653d6f6e015e7459ee62cdab259316c0537
ep_bytes: 558bec83c4f0b89c7c4100e86cabfeff
timestamp: 1992-06-19 22:22:17

Version Info:

Comments:
CompanyName: koasols
FileDescription: 8000009 0.1009 Installation
FileVersion: 0.1009
LegalCopyright: koasols
Translation: 0x0409 0x04e4

Trojan:Win32/QHosts.BF also known as:

BkavW32.AIDetectMalware
DrWebTrojan.Hosts.6553
MicroWorld-eScanGen:Heur.SMHeist.1
FireEyeGen:Heur.SMHeist.1
CAT-QuickHealBAT/Qhost.AF
McAfeeGeneric StartPage.sim
Cylanceunsafe
SangforTrojan.Win32.Bicololo.Vrs4
K7AntiVirusTrojan ( 003982501 )
AlibabaTrojanDownloader:Win32/QHosts.2935787c
K7GWTrojan ( 003982501 )
Cybereasonmalicious.df640e
CyrenW32/Qhost.M.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Bicololo.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Bicololo
BitDefenderGen:Heur.SMHeist.1
NANO-AntivirusTrojan.Script.Qhost.cjeaqy
SUPERAntiSpywareTrojan.Agent/Gen-BIcololo
AvastBV:Bicololo-CD [Trj]
TencentWin32.Trojan.Dropper.Sgil
EmsisoftGen:Heur.SMHeist.1 (B)
F-SecureMalware.VBS/Bicololo.N
VIPREGen:Heur.SMHeist.1
McAfee-GW-EditionBehavesLike.Win32.ObfuscatedPoly.cm
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
GDataGen:Heur.SMHeist.1
AviraTR/Dropper.Gen
XcitiumTrojWare.Win32.Bicololo.AA@51cpp4
ArcabitTrojan.SMHeist.1
ZoneAlarmHEUR:Trojan-Downloader.Script.Generic
MicrosoftTrojan:Win32/QHosts.BF
GoogleDetected
ALYacGen:Heur.SMHeist.1
MAXmalware (ai score=100)
PandaTrj/CI.A
YandexTrojan.Qhosts!W9gEaMTRx4w
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bicololo.A!tr
AVGBV:Bicololo-CD [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Trojan:Win32/QHosts.BF?

Trojan:Win32/QHosts.BF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment