Trojan

Should I remove “Trojan:Win32/QQPass!pz”?

Malware Removal

The Trojan:Win32/QQPass!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/QQPass!pz virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/QQPass!pz?


File Info:

name: BA52050054FD557CA26C.mlw
path: /opt/CAPEv2/storage/binaries/27a31fd3a6d754ae582a3cbb0e47704d6e0b2ceab145014317d4e69ef7146e3a
crc32: FA64060C
md5: ba52050054fd557ca26ccacbd3077899
sha1: 76d828bc42268a5ca94cf23cf5ffd0b463a6d847
sha256: 27a31fd3a6d754ae582a3cbb0e47704d6e0b2ceab145014317d4e69ef7146e3a
sha512: c2133ffbff4c9ae83018dda9ff96c356a62596f0e30f0a75998c1d5c432c84b77e1285a8562ecb489ba056cd58aca7dc26a4aaab3382dcb59c4710c8ab3f4403
ssdeep: 3072:8CaoAs101bol0xPTM7mRCAdJSSxPUkl3V4Vh1ZMQTCk/dN92sdNhavtrVdewnAx0:8qDAMl0xPTMiR9JSSxPUKuzdodH1m6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E7C408133222CC51F2D0D7B6A2A58775FA709B4528F2C903FAACBE167F706534E6D50A
sha3_384: 358de2ddf36be7eeffb1ffe888d98347a06d34d048eeed83edfe5ac35b0426f75c888ae31a1d82ef2904b45a6e15a620
ep_bytes: e85bc20300e8b0a9030033c0c3909090
timestamp: 2015-01-28 13:36:24

Version Info:

0: [No Data]

Trojan:Win32/QQPass!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader12.31656
MicroWorld-eScanGeneric.Dacic.AAD0835C.A.D05C0371
McAfeeTrojan-FFZL!BA52050054FD
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.QQPass.Win32.24502
SangforTrojan.Win32.Save.ShadowBrokersC
K7AntiVirusPassword-Stealer ( 004b75691 )
K7GWPassword-Stealer ( 004b75691 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36738.IqY@a8A8wXc
VirITTrojan.Win32.Dnldr12.BUVO
CyrenW32/QQPass.AI.gen!Eldorado
SymantecSMG.Heur!gen
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/PSW.QQPass.OWD
APEXMalicious
ClamAVWin.Malware.Dqqw-9951425-0
KasperskyTrojan.Win32.Scar.oetk
BitDefenderGeneric.Dacic.AAD0835C.A.D05C0371
NANO-AntivirusTrojan.Win32.DangerousObject.dnizrq
AvastWin32:QQPass-WK [Trj]
TencentTrojan.Win32.Sdum.ki
EmsisoftGeneric.Dacic.AAD0835C.A.D05C0371 (B)
F-SecureTrojan.TR/PSW.QQSteal.boeu
BaiduWin32.Trojan-PSW.QQPass.af
VIPREGeneric.Dacic.AAD0835C.A.D05C0371
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.ba52050054fd557c
SophosTroj/Agent-BCIH
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.19GZR9J
JiangminTrojan/Generic.bbckw
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/PSW.QQSteal.boeu
MAXmalware (ai score=84)
Antiy-AVLVirus/Win32.Expiro.imp
Kingsoftmalware.kb.a.999
ArcabitGeneric.Dacic.AAD0835C.A.D05C0371
ZoneAlarmTrojan.Win32.Scar.oetk
MicrosoftTrojan:Win32/QQPass!pz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Scar.R503186
VBA32BScope.Trojan.Inject
ALYacGeneric.Dacic.AAD0835C.A.D05C0371
Cylanceunsafe
PandaTrj/Genetic.gen
RisingStealer.QQPass!1.A658 (CLASSIC)
YandexTrojan.GenAsa!5k90ukTn350
IkarusTrojan.Vundo
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/QQPass.WK!tr
AVGWin32:QQPass-WK [Trj]
Cybereasonmalicious.c42268
DeepInstinctMALICIOUS

How to remove Trojan:Win32/QQPass!pz?

Trojan:Win32/QQPass!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment