Malware

Win32/PSW.QQPass.OGW removal

Malware Removal

The Win32/PSW.QQPass.OGW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/PSW.QQPass.OGW virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/PSW.QQPass.OGW?


File Info:

name: DAE0E0F07787B509717E.mlw
path: /opt/CAPEv2/storage/binaries/4c910d0c7f994f697530e4b999c8288df933668400dc6f26fd6ca0f091764715
crc32: B564DEDC
md5: dae0e0f07787b509717e10df9e4ab268
sha1: b4270e8aa1497d350782387b323b8e36054d6124
sha256: 4c910d0c7f994f697530e4b999c8288df933668400dc6f26fd6ca0f091764715
sha512: a8a1a66a9f6c2d1012739abd9b9ca8186dfe7b70a1a38e671c32bdd021cf58a8834985c02f11757edbe7426f3a872efc0443c56004c1ed32d2f751bf163fb0a3
ssdeep: 98304:nFi0Ym0240d30KW0pJ01K0gp0mO02kVDFYOYZg:jVBYO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17C165350E255CC62D81E4BB1C9B685F010E3BDACE8F1421F71A9BE1939B3382459DBDE
sha3_384: c561dfc6dcbad480a87d7ea11ab0ee900668a53737efdcbcbf00753e651912166aba433d127df224557efd98b66d0bc5
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2012-10-07 11:22:48

Version Info:

0: [No Data]

Win32/PSW.QQPass.OGW also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.70085840
FireEyeGeneric.mg.dae0e0f07787b509
SkyhighGenericRXWG-DA!3B6638164297
ALYacTrojan.GenericKD.70085840
MalwarebytesGeneric.Malware/Suspicious
VIPRETrojan.GenericKD.70085840
SangforInfostealer.Win32.Agent.V6xv
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojanPSW:Win32/QQPass.7b7ddf3a
ArcabitTrojan.Generic.D42D6CD0
BitDefenderThetaGen:NN.ZexaE.36792.@BWbaKRWONpi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.QQPass.OGW
APEXMalicious
CynetMalicious (score: 100)
BitDefenderTrojan.GenericKD.70085840
RisingStealer.QQPass!8.F7 (CLOUD)
EmsisoftTrojan.GenericKD.70085840 (B)
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Sasfis.ytk
GoogleDetected
MAXmalware (ai score=86)
Antiy-AVLTrojan[PSW]/Win32.QQPass
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.1DPEYYJ
McAfeeArtemis!DAE0E0F07787
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Agent
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H06JR23
TencentWin32.Trojan-PSW.2.Lqil
IkarusTrojan-Downloader.Win32.Small
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/QQPass.OGW!tr
AVGWin32:Malware-gen
Cybereasonmalicious.aa1497
AvastWin32:Malware-gen

How to remove Win32/PSW.QQPass.OGW?

Win32/PSW.QQPass.OGW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment