Spy Trojan

UDS:Trojan-Spy.Win32.Pophot.dqwr removal

Malware Removal

The UDS:Trojan-Spy.Win32.Pophot.dqwr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-Spy.Win32.Pophot.dqwr virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine UDS:Trojan-Spy.Win32.Pophot.dqwr?


File Info:

name: B523884312031F502B8D.mlw
path: /opt/CAPEv2/storage/binaries/76e4adde48befbb6a3379baab4da49fcc9513a0232514d2e32447817e149d4fb
crc32: AB3B7A26
md5: b523884312031f502b8d26eb6c273725
sha1: 8d99f2f24f112cf067b39eafa7af2e814e350741
sha256: 76e4adde48befbb6a3379baab4da49fcc9513a0232514d2e32447817e149d4fb
sha512: e6d91df8184d91ec21fb58833cd93893706af0f83975c6c789424dc7a6672abc28cd789f3cbb7e0b1b9039effa4a85e7da71408f7c39fe3aaec3958632d39430
ssdeep: 768:oC1qpQpH1hiw0ystn5whDR6BlV9QzJVs/4XKdXmRifqrqtOCge3b8x:P1qpQpH13sBahd7zJYdXmuUNe3Ix
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T191135C27B3E24470E460CABD1C38B221EF7F7CB22DA0117A676845AE4D65B919CD8773
sha3_384: c7c3f9ce3d49d55dcd7f88ea5032c088dea8867bd989ab9afa2de8194284956221108d15653489dfe78ed126ccd95bc5
ep_bytes: 558bec83c4f0535657a1b0934000c600
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

UDS:Trojan-Spy.Win32.Pophot.dqwr also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Pophot.lHd2
Elasticmalicious (moderate confidence)
CynetMalicious (score: 100)
SkyhighBehavesLike.Win32.Worm.ph
McAfeeArtemis!B52388431203
Cylanceunsafe
SangforTrojan.Win32.Agent.Vupf
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Generic.AGQR
KasperskyUDS:Trojan-Spy.Win32.Pophot.dqwr
SUPERAntiSpywareTrojan.Agent/Gen-Delf
AvastWin32:Malware-gen
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDownloader.Small.aiaf
VaristW32/A-98954f5c!Eldorado
Kingsoftmalware.kb.a.932
ZoneAlarmUDS:Trojan-Spy.Win32.Pophot.dqwr
GoogleDetected
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTROJ_GEN.R002H07AH24
RisingTrojan.Generic@AI.98 (RDML:0ie00e+lmcNWwp//9CN/8w)
IkarusTrojan-Spy.Win32.Pophot
MaxSecureTrojan.Malware.213788765.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
Cybereasonmalicious.24f112
DeepInstinctMALICIOUS

How to remove UDS:Trojan-Spy.Win32.Pophot.dqwr?

UDS:Trojan-Spy.Win32.Pophot.dqwr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment