Crack

Win32:Patched-WQ [Trj] (file analysis)

Malware Removal

The Win32:Patched-WQ [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Patched-WQ [Trj] virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine Win32:Patched-WQ [Trj]?


File Info:

name: 3E0A6FAFA6C4BDD91EA3.mlw
path: /opt/CAPEv2/storage/binaries/b96f7f82da20746e2f2a64fc537e04c066ba0403795b1771ac1a19bc8d296936
crc32: BAFEC456
md5: 3e0a6fafa6c4bdd91ea34e896412e0c3
sha1: 0964e46e6df25538de0ff7246a53df3dfba26256
sha256: b96f7f82da20746e2f2a64fc537e04c066ba0403795b1771ac1a19bc8d296936
sha512: f1ab8164e4a75c1e5d18068bfe1a2814356d408f899e7346e27261d41d91b452a59874b3762924365f13cd4abb94207357eb34054f53b58dfa0ed351fb343be6
ssdeep: 768:3tV5ODo6YBDqH2kutK2JMwoykWYtcK9OSqyKSlNB:3Uo6Gq/+Klftc21qhMv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T148C25C136BD641B2F5A1A6B40DB67619E777E9C047219EC713103E0F49223D36CBA293
sha3_384: 4de9ea8844b6b20b9dab23b9f59ad3c8750d5af26cce6c45abb91b379c58dd6cde88a777127020d68fc25b1eff90dac7
ep_bytes: 683c504000e934060000e80f00000043
timestamp: 2005-06-15 09:57:43

Version Info:

CompanyName: Nikon Corporation
FileDescription: PTP/IP Enumerator
FileVersion: 1.0.0.3210
InternalName: NkPtpEnum
LegalCopyright: Copyright (C) Nikon Corporation 2005. Portions of this software are copyright (C) 2004-2005 FotoNation Inc.
OriginalFilename: NkPtpEnum.exe
ProductName: PTP/IP Enumerator
ProductVersion: 1.0.0.3130
Translation: 0x0409 0x04b0

Win32:Patched-WQ [Trj] also known as:

BkavW32.PatchedZB.PE
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Patched.HE
FireEyeTrojan.Patched.HE
CAT-QuickHealW32.Patchload.O
ALYacTrojan.Patched.HE
MalwarebytesMalware.Heuristic.1003
VIPRETrojan.Patched.HE
K7AntiVirusTrojan ( 0026f5d91 )
K7GWTrojan ( 0026f5d91 )
Cybereasonmalicious.fa6c4b
ArcabitTrojan.Patched.HE
VirITWin32.Yoshi.E
CyrenW32/Patched.G
SymantecTrojan.Paccyn!inf
ESET-NOD32Win32/Patched.HN
BaiduWin32.Virus.Loader.l
TrendMicro-HouseCallPTCH_KATUSHA.W
CynetMalicious (score: 99)
KasperskyTrojan-Spy.Win32.Zbot.gen
BitDefenderTrojan.Patched.HE
NANO-AntivirusTrojan.Win32.Patched.dwgwe
AvastWin32:Patched-WQ [Trj]
TencentVirus.Win32.Patched.mf
Ad-AwareTrojan.Patched.HE
ComodoTrojWare.Win32.Patched.HN@3bsert
DrWebTrojan.Starter.1695
TrendMicroPTCH_KATUSHA.W
McAfee-GW-EditionBehavesLike.Win32.Virut.mm
SophosW32/Patched-AL
APEXMalicious
JiangminTrojanSpy.Zbot.adxr
AviraW32/Patchload.A
Antiy-AVLTrojan/Generic.ASVirus.2BD
MicrosoftVirus:Win32/Patchload.O
ViRobotWin32.Patched.BE
GDataTrojan.Patched.HE
TACHYONVirus/W32.Patched.Gen
AhnLab-V3Win-Trojan/Patched.DD
McAfeeW32/Katusha
MAXmalware (ai score=87)
VBA32Trojan-Spy.Zbot.gen
ZonerProbably Heur.ExeHeaderL
RisingVirus.Loader!1.9B09 (CLASSIC)
YandexWin32.Katusha.Gen
IkarusVirus.Win32.Patchload
MaxSecureVirus.W32.Patched.MF
FortinetW32/Patched.MF!tr
AVGWin32:Patched-WQ [Trj]
PandaW32/Katusha.BN
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Win32:Patched-WQ [Trj]?

Win32:Patched-WQ [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment