Trojan

Should I remove “Trojan:Win32/Qqrob!ic”?

Malware Removal

The Trojan:Win32/Qqrob!ic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Qqrob!ic virus can do?

  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Qqrob!ic?


File Info:

name: 85761E1F2D6D827B23EA.mlw
path: /opt/CAPEv2/storage/binaries/6fd6be9c6b41af0242f695809da2d20629716f4498cb8115bcc16a9ba33ac58f
crc32: 4DCFE367
md5: 85761e1f2d6d827b23eaf64be99b6035
sha1: 5be31f5f3f34b751bfa1ee7d2c26508fadea052b
sha256: 6fd6be9c6b41af0242f695809da2d20629716f4498cb8115bcc16a9ba33ac58f
sha512: d179e9e49b1d442da49ab1c8fe52aa534f05ccbcdb6c40a8ea3d533e5fd3173e1dd49d19665d3ff890e5b4219ece046bc6786355cd2e47a854cf4a9f37c0ec9c
ssdeep: 6144:Kdy+bnr+Hp0yN90QEILK3kWanZNzdZqWXKqJXpLk:nMrny90N4jaqJZLk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18074F113A7E89432E9B1177419F602C30B397DA65D7887AF3355695E4CB22C4A8323BF
sha3_384: 24d8f3ce167631407ebe589739d069dfbebe2e2a2dd9a9155bbe2f591abbf5356ce05f922d391fddea639a0c1bc511e4
ep_bytes: e8f0060000e9000000006a5868b87240
timestamp: 2022-05-24 22:49:06

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Win32 Cabinet Self-Extractor
FileVersion: 11.00.17763.1 (WinBuild.160101.0800)
InternalName: Wextract
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: WEXTRACT.EXE .MUI
ProductName: Internet Explorer
ProductVersion: 11.00.17763.1
Translation: 0x0409 0x04b0

Trojan:Win32/Qqrob!ic also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.Y!c
DrWebTrojan.Inject4.58123
MicroWorld-eScanTrojan.Generic.33926819
FireEyeTrojan.Generic.33926819
CAT-QuickHealTrojan.GenericPMF.S30228938
McAfeeArtemis!85761E1F2D6D
Cylanceunsafe
ZillyaTrojan.Agent.Win32.3525836
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 0059955a1 )
AlibabaTrojanSpy:MSIL/Stealer.75d5645f
K7GWSpyware ( 0059955a1 )
Cybereasonmalicious.f3f34b
VirITTrojan.Win32.GenusT.DMKL
CyrenW32/Kryptik.JKR.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
ClamAVWin.Packed.Lazy-9958163-0
BitDefenderTrojan.Generic.33926819
NANO-AntivirusTrojan.Win32.Inject4.jwrecz
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:CrypterX-gen [Trj]
TencentMsil.Trojan.Redline.Gkjl
EmsisoftTrojan.Generic.33926819 (B)
F-SecureTrojan.TR/AD.Nekark.acgzd
VIPRETrojan.Generic.33926819
TrendMicroTROJ_GEN.R002C0DF923
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SophosTroj/PlugX-EC
SentinelOneStatic AI – Malicious SFX
GDataWin32.Trojan.PSE.1I5EP69
JiangminTrojan.MSIL.aocbf
AviraTR/AD.Nekark.acgzd
Antiy-AVLTrojan[Spy]/MSIL.RedLine
ArcabitTrojan.Generic.D205AEA3
ZoneAlarmHEUR:Trojan-PSW.MSIL.Reline.pef
MicrosoftTrojan:Win32/Qqrob!ic
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.TrojanX-gen.C5438269
ALYacTrojan.Generic.33926819
MAXmalware (ai score=80)
MalwarebytesTrojan.Dropper.CAB
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0DF923
RisingStealer.Agent!1.E5F0 (CLASSIC)
YandexTrojan.Disabler!G6z7qDxyklM
IkarusTrojan-Spy.MSIL.Redline
FortinetW32/GenKryptik.GKKY!tr
AVGWin32:CrypterX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Qqrob!ic?

Trojan:Win32/Qqrob!ic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment