Malware

Win32/Qhost.OLD removal guide

Malware Removal

The Win32/Qhost.OLD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Qhost.OLD virus can do?

  • Executable code extraction
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to disable UAC
  • The sample wrote data to the system hosts file.
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

www.renscubaworx.com

How to determine Win32/Qhost.OLD?


File Info:

crc32: 78213C38
md5: 410737100ac24d1125eb9244ab7c2161
name: 410737100AC24D1125EB9244AB7C2161.mlw
sha1: 7d30a0f075cf2ed3b124234e3255dc9baa8f6fad
sha256: a705766e97b4514de2dbebd638c914d8c3267ccd2e3455f6a265771f18b46d14
sha512: cd854df0fddc4f2f74575592d2bfd3d962d9039b5ab8670df22b48675d5fe5524993298c339db16adaecf011ce07218571064d3d9f623ee020d5d4a7b3b47158
ssdeep: 192:spnUvm6og5mJSouxYfFAAhOXc7ryFuDB2Q/ryNEprU4HtXBtxEhmnyqt+D30SF4:spn2Z7+tFAAhjb/HpIwtLoD30SG6b
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0c0a 0x04b0
LegalCopyright: Adobe Macromedia
InternalName: Adobe
FileVersion: 1.00.0017
CompanyName: D3xt3r
ProductName: Adobe
ProductVersion: 1.00.0017
OriginalFilename: Adobe.exe

Win32/Qhost.OLD also known as:

BkavW32.Common.5826B23D
K7AntiVirusRiskware ( 0015e4f01 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader4.41716
CynetMalicious (score: 99)
ALYacGen:Trojan.VBMalware.bm0@aWftftU
CylanceUnsafe
ZillyaTrojan.Qhost.Win32.7721
AlibabaRansom:Win32/Blocker.72f61c0d
K7GWRiskware ( 0015e4f01 )
Cybereasonmalicious.00ac24
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Qhost.OLD
APEXMalicious
AvastFileRepMetagen [Malware]
KasperskyTrojan-Ransom.Win32.Blocker.bljf
BitDefenderGen:Trojan.VBMalware.bm0@aWftftU
NANO-AntivirusTrojan.Win32.Dwn.ofuge
ViRobotTrojan.Win32.Generic.28672.I
MicroWorld-eScanGen:Trojan.VBMalware.bm0@aWftftU
TencentWin32.Trojan.Blocker.Oyep
Ad-AwareGen:Trojan.VBMalware.bm0@aWftftU
ComodoSuspicious@#2gaa7akg44cep
BitDefenderThetaAI:Packer.EC4FF5CD1E
VIPRETrojan.Win32.Generic!SB.0
McAfee-GW-EditionBehavesLike.Win32.Trojan.mz
FireEyeGeneric.mg.410737100ac24d11
EmsisoftGen:Trojan.VBMalware.bm0@aWftftU (B)
WebrootW32.Malware.Gen
AviraTR/VB.Downloader.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.E914A3
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Malat
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Trojan.VBMalware.bm0@aWftftU
McAfeeArtemis!410737100AC2
MAXmalware (ai score=100)
PandaGeneric Malware
IkarusTrojan.Win32.Cossta
FortinetW32/Dx.BAKF!tr
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml

How to remove Win32/Qhost.OLD?

Win32/Qhost.OLD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment