Trojan

Should I remove “VHO:Trojan-Banker.Win32.Qbot”?

Malware Removal

The VHO:Trojan-Banker.Win32.Qbot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:Trojan-Banker.Win32.Qbot virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Anomalous binary characteristics

Related domains:

edgedl.me.gvt1.com

How to determine VHO:Trojan-Banker.Win32.Qbot?


File Info:

crc32: 4281E45A
md5: e8f3bcb2560827a8aee38e739fe927af
name: E8F3BCB2560827A8AEE38E739FE927AF.mlw
sha1: 2468ca8a3ddf6c763b7e9378fc4676d90a3f5637
sha256: 0d82df77582d5ea4c734ccac7c0c6559398e0ff942d8ce49772713b47667380b
sha512: 1c49dadeb8ec383ec78b8188d24d72ac9bb39602215ad95de5412228ac104fda38aeb51f160f132e6285101f67f45d1b070671f21c4c5e7c0b2d421bac09fcac
ssdeep: 6144:9/st+16ZWiobj+n5QZRO0Xj/Ee+aRLvccAOPyI:A+QoOaEFA7RD
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

VHO:Trojan-Banker.Win32.Qbot also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.Qbot.10
ALYacTrojan.GenericKD.47025694
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 00587f7c1 )
K7AntiVirusTrojan ( 00587f7c1 )
CyrenW32/Qbot.FS.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMPI
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
CynetMalicious (score: 100)
KasperskyVHO:Trojan-Banker.Win32.Qbot.gen
BitDefenderTrojan.GenericKD.47025694
MicroWorld-eScanTrojan.GenericKD.47025694
Ad-AwareTrojan.GenericKD.47025694
SophosMal/EncPk-APW
BitDefenderThetaGen:NN.ZedlaF.34170.tq6@auyBbhji
FireEyeGeneric.mg.e8f3bcb2560827a8
EmsisoftTrojan.GenericKD.47025694 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Kryptik.jwgnd
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftTrojan:Win32/Qakbot.SM!MTB
GridinsoftTrojan.Win32.Banker.oa!s1
ArcabitTrojan.Generic.D2CD8E1E
GDataTrojan.GenericKD.47025694
AhnLab-V3Trojan/Win.Qakbot.C4646974
McAfeeGenericRXAA-AA!E8F3BCB25608
MAXmalware (ai score=85)
MalwarebytesQbot.Backdoor.Stealer.DDS
RisingTrojan.Generic@ML.94 (RDML:LcoIK2KuxsCI5ondc8evog)
MaxSecureTrojan.Malware.122357315.susgen
FortinetW32/Kryptik.HLAD!tr
AVGWin32:MalwareX-gen [Trj]

How to remove VHO:Trojan-Banker.Win32.Qbot?

VHO:Trojan-Banker.Win32.Qbot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment