Malware

Win32/Qbot.CC information

Malware Removal

The Win32/Qbot.CC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Qbot.CC virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Drops a binary and executes it
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/Qbot.CC?


File Info:

crc32: CC4428FE
md5: cd8448f7c035708dfa07517034f285a6
name: 444444.png
sha1: 199ceb462f30d57e3f6ed3a792d0f70461a5a3a0
sha256: f6f1dfc3a020e61fabb78326e88401e45d7bc6c03a67e07a88ebb15703b11b79
sha512: 34b125b4e87f572a1db2b85e26262329378466e51e953c2058653f5e29b7addc5af523d981e07555c22b2cfd71c19c4e83c62b6832cb54918470987024d5eb75
ssdeep: 24576:3oy/aO0r1oNp3PKfa7dQjtIufNkwKZCYXK1qp4jXv0hKjrm:3oy/aO0ryNxPL78JfNZFHXm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9River Symphony Solutions Process anbed bri
InternalName: Noun Eastwork
FileVersion: 14.1.28.72
CompanyName: River Symphony Solutions
BuildID: 32294754
LegalTrademarks: Noun Eastwork Glass Le River Symphony Solutions
ProductName: Noun Eastwork
ProductVersion: 14.1.28.72
FileDescription: Noun Eastwork
OriginalFilename: Foo.exe
Translation: 0x0000 0x04b0

Win32/Qbot.CC also known as:

CylanceUnsafe
RisingTrojan.Qbot!8.8A3 (C64:YzY0Om7Eu3oLhzJY)
WebrootW32.Trojan.Gen
Endgamemalicious (moderate confidence)
MicrosoftTrojan:Win32/Wacatac.C!ml
ESET-NOD32Win32/Qbot.CC
SentinelOneDFI – Suspicious PE
BitDefenderThetaGen:NN.ZexaF.34090.!u0@a0@RfCli

How to remove Win32/Qbot.CC?

Win32/Qbot.CC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment