Trojan

Trojan:Win32/QQPass!pz removal tips

Malware Removal

The Trojan:Win32/QQPass!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/QQPass!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan:Win32/QQPass!pz?


File Info:

name: 86397AEFBACBE28342C2.mlw
path: /opt/CAPEv2/storage/binaries/34896949d25b6971d47cc5dcf24f1214abb223fd4c77392476c8d232e32004db
crc32: 4406CB8A
md5: 86397aefbacbe28342c2042ca01ccbdb
sha1: 950016d5bc54d26aec9574ab6d4fcf989d41ff04
sha256: 34896949d25b6971d47cc5dcf24f1214abb223fd4c77392476c8d232e32004db
sha512: c16d9ea230715f8c0030603d7e4662b3e266c0b6a6a70603eacc4e476789070bb9924599fbb78a32d6ae1bdaf865fbe5aee48b06fd6fbcb7d68cd77a77065484
ssdeep: 3072:RiCaoAs101Pol0xPTM7mRCAdJSSxPUkl3V1MQTCk/dN92sdNhavtrVdewnAx3wm6:RiqDAwl0xPTMiR9JSSxPUKpdodHf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BAC4F8137721CC61F5E057B6A2B6C33476B49A1435B3DA13BBECAC62BF702518B1E50A
sha3_384: f60eb05732bcc4da6c5d0613b0bb2ded4f769b6e4fd186767350988a16d5ba1445ad34a3baf32e1cdeadf649cc3adf17
ep_bytes: e85bc20300e8b0a9030033c0c3909090
timestamp: 2015-01-28 13:36:24

Version Info:

0: [No Data]

Trojan:Win32/QQPass!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Zusy.451734
FireEyeGeneric.mg.86397aefbacbe283
CAT-QuickHealTrojan.GenericPMF.S19447789
SkyhighBehavesLike.Win32.RAHack.hm
ALYacGen:Variant.Zusy.451734
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Scar.Win32.137796
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
BitDefenderGen:Variant.Zusy.451734
K7GWTrojan ( 005ab0081 )
Cybereasonmalicious.5bc54d
BaiduWin32.Trojan-PSW.QQPass.af
VirITTrojan.Win32.Generic.ATOF
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/PSW.QQPass_AGen.H
APEXMalicious
ClamAVWin.Malware.Dqqw-9951425-0
KasperskyTrojan.Win32.Scar.oetk
RisingStealer.QQPass!1.A658 (CLASSIC)
SophosMal/QQPass-O
F-SecureTrojan.TR/PSW.QQSteal.boeu
DrWebTrojan.DownLoader12.31656
VIPREGen:Variant.Zusy.451734
TrendMicroTROJ_GEN.R03BC0DK623
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Zusy.451734 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=85)
JiangminTrojan/Generic.bbckw
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/PSW.QQSteal.boeu
VaristW32/QQPass.AS.gen!Eldorado
Antiy-AVLTrojan[Dropper]/Win32.Dinwod.acqn
Kingsoftmalware.kb.b.950
MicrosoftTrojan:Win32/QQPass!pz
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Zusy.D6E496
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmTrojan.Win32.Scar.oetk
GDataWin32.Trojan.PSE.19GZR9J
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Scar.R567324
Acronissuspicious
McAfeeGenericRXES-IH!86397AEFBACB
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DK623
TencentTrojan.Win32.Scar.16000124
YandexTrojan.DownLoader!G9lFQfoV/hQ
IkarusTrojan.Vundo
MaxSecureTrojan.Scar.OETK
FortinetW32/Generic.AC.38A19A
BitDefenderThetaGen:NN.ZexaF.36792.KmX@a8kkoyd
AVGWin32:QQPass-WK [Trj]
AvastWin32:QQPass-WK [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/QQPass!pz?

Trojan:Win32/QQPass!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment