Trojan

Trojan:Win32/QQPass!pz removal

Malware Removal

The Trojan:Win32/QQPass!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/QQPass!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/QQPass!pz?


File Info:

name: F604E227C174DD68A6F0.mlw
path: /opt/CAPEv2/storage/binaries/f07dd8119721d5ebb73eb835b37614c309594f860ab6104d530852dfbd74708e
crc32: 4D6A54BD
md5: f604e227c174dd68a6f0cf36e63c08a8
sha1: b8009cc2586572411678b74e9d10693d3040b4d3
sha256: f07dd8119721d5ebb73eb835b37614c309594f860ab6104d530852dfbd74708e
sha512: 7796c8192525c158392d34ebf3c0120d66c8b7665404a8c959e024ddfb8d6adaac3e76f1dcc31374acacf52dfb989fd43c1a3a4273e9124dded9a0aca5279c25
ssdeep: 768:4L8JdIxlNbsD3Wytdfhu9FlBVsCPlCmEntSynDY87dVROCDhZEraficg8RT2upMP:4LKCxc6ythktVsC9bMn7PoC3txg89Fpm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T198236A1A1AAF950CF365C8B760216CCBEC014FD76AE8D0409877671E9E61F0B9CFE925
sha3_384: cfa3c64ee8ee69a6eb24faa43fa4457461b584ebdeee1ac6244237123750689630bb386aece81a8aea61f3a8bf816c07
ep_bytes: b8402e49005064ff3500000000648925
timestamp: 2015-01-28 13:36:24

Version Info:

0: [No Data]

Trojan:Win32/QQPass!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.QQPass.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.f604e227c174dd68
SkyhighBehavesLike.Win32.Generic.pc
SangforInfostealer.Win32.QQPass.V3gh
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojan:Win32/QQPass.2983a942
K7GWTrojan ( 004bcce41 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
tehtrisGeneric.Malware
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Generic-9918314-0
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
RisingStealer.QQPass!8.F7 (TFE:4:T7B0gEUamEH)
SophosMal/QQPass-O
TrendMicroTROJ_GEN.R03BC0DLQ23
IkarusTrojan.Win32.QQpass
VaristW32/Ulise.Q.gen!Eldorado
Antiy-AVLTrojan/Win32.Scar
Kingsoftmalware.kb.b.912
MicrosoftTrojan:Win32/QQPass!pz
GDataWin32.Trojan.PSE.1FSA1AM
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R292056
McAfeeGenericRXAA-FA!F604E227C174
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallTROJ_GEN.R03BC0DLQ23
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.74529223.susgen
FortinetW32/Agent.C8AC!tr
DeepInstinctMALICIOUS

How to remove Trojan:Win32/QQPass!pz?

Trojan:Win32/QQPass!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment