Malware

Win32/Qhost.PNU removal instruction

Malware Removal

The Win32/Qhost.PNU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Qhost.PNU virus can do?

  • The sample wrote data to the system hosts file.

How to determine Win32/Qhost.PNU?


File Info:

crc32: EC30A97C
md5: 99ad238bb185ffedf55854016da03536
name: 99AD238BB185FFEDF55854016DA03536.mlw
sha1: 6c34b80db38a1c79f06c943d544778f5334dcc7e
sha256: 5a56c2ac2581e0d972685542787e65f3b37489af9f61637b534c33a31a44b6d6
sha512: 52c6a2a369dec5eabcea4dc4382d210f3219846b4b68f6abdf1d51b41633aaa344095431729620cd38b270a153fc5b4323c6e12aa52d890d441ff04bd20dec93
ssdeep: 3072:V9ruj40JzlpFyXAUKjqztMrx/k4htXlG4gAg0Fujb4JVyRoi:e/uKWztMv7gAOhRo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Qhost.PNU also known as:

BkavW32.RansomXpackT.Trojan
K7AntiVirusTrojan ( 0055485d1 )
CylanceUnsafe
ZillyaTrojan.Hosts2.Win32.871
SangforTrojan.Win32.Dynamer.8
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Qhost.c6db24e2
K7GWTrojan ( 0055485d1 )
Cybereasonmalicious.bb185f
CyrenW32/S-05856bbf!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Qhost.PNU
APEXMalicious
AvastFileRepMetagen [Malware]
CynetMalicious (score: 85)
KasperskyTrojan.Win32.Hosts2.gen
NANO-AntivirusTrojan.Win32.Hosts2.elsavy
SUPERAntiSpywareAdware.ConvertAd/Variant
TencentMalware.Win32.Gencirc.10b454f3
SophosMal/Generic-R + Mal/Qhost-M
ComodoTrojWare.Win32.Qhosts.BF@73wqrc
BitDefenderThetaGen:NN.ZexaF.34628.mCW@ayNnqRli
VIPREBehavesLike.Win32.Malware.sfm (mx-v)
TrendMicroTROJ_GEN.R002C0RAK21
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
EmsisoftGen:Variant.Mikey.58065 (B)
AviraHEUR/AGEN.1116522
ArcabitTrojan.Mikey.DE2D1
ZoneAlarmTrojan.Win32.Hosts2.gen
AhnLab-V3Trojan/Win32.Hosts.R194465
McAfeeGenericRXAA-AA!99AD238BB185
VBA32Win32.Trojan.Hoster.Heur
MalwarebytesGeneric.Trojan.Malicious.DDS
RisingTrojan.QHosts!8.52B (CLOUD)
YandexTrojan.GenAsa!DvAobRVNtKs
eGambitUnsafe.AI_Score_99%
AVGFileRepMetagen [Malware]
Qihoo-360Win32/Trojan.Hosts2.HgAASQoA

How to remove Win32/Qhost.PNU?

Win32/Qhost.PNU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment