Malware

How to remove “Win32/Qhost.PED”?

Malware Removal

The Win32/Qhost.PED is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Qhost.PED virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Qhost.PED?


File Info:

crc32: 39B38C05
md5: c2bac3b1f9e3a789e36ed25092b67a06
name: C2BAC3B1F9E3A789E36ED25092B67A06.mlw
sha1: e002e819be14c0954f4d15f26290c051810658a8
sha256: 4c54f67521fd8caccc8fcc7c058fb2f48682bd57bf7c597c161b35a8d23ab35f
sha512: 64a4b4a4a4c72882eb1d58ab3a550f7f23126212bc3a6fe40c95e953259377cd61028bebef089be2c5999cc4d459978f1ab76b6ad4341ed683e0a5ff1f1636c7
ssdeep: 6144:727gCbTehEqclWYac67TJx4dGazSDKTsmReZGVrV:727/bTehEqclr0mimIZGb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Qhost.PED also known as:

DrWebTrojan.Hosts.6156
CynetMalicious (score: 99)
ALYacGen:Trojan.Heur.DP.cKW@aaaKr7l
CylanceUnsafe
Cybereasonmalicious.1f9e3a
BaiduWin32.Trojan.Generic.u
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Qhost.PED
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Ag-9
KasperskyTrojan-Ransom.Win32.Gimemo.arvh
BitDefenderGen:Trojan.Heur.DP.cKW@aaaKr7l
NANO-AntivirusTrojan.Win32.Gimemo.duisfi
MicroWorld-eScanGen:Trojan.Heur.DP.cKW@aaaKr7l
TencentWin32.Trojan.Gimemo.Syhu
SophosMal/Generic-S
ComodoMalware@#17esa6bf7igvh
F-SecureTrojan.TR/Spy.43520.205
BitDefenderThetaAI:Packer.E99AD09B1C
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Emotet.cc
FireEyeGen:Trojan.Heur.DP.cKW@aaaKr7l
EmsisoftGen:Trojan.Heur.DP.cKW@aaaKr7l (B)
JiangminTrojan/Gimemo.ejj
AviraTR/Dropper.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Heur.DP.EB1D85
ZoneAlarmTrojan-Ransom.Win32.Gimemo.arvh
GDataGen:Trojan.Heur.DP.cKW@aaaKr7l
AhnLab-V3Trojan/Win32.Chifrax.C160330
McAfeeArtemis!C2BAC3B1F9E3
MAXmalware (ai score=89)
VBA32Hoax.Gimemo
MalwarebytesTrojan.Dropper.SFXAI
PandaTrj/CI.A
RisingRansom.Gimemo!8.306 (CLOUD)
YandexTrojan.GenAsa!nIHrkMdLyF8
IkarusTrojan-Ransom.Gimemo
FortinetW32/Qhost.PED!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Win32/Qhost.PED?

Win32/Qhost.PED removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment