PUA

How to remove “Win32:Qqhack-E [PUP]”?

Malware Removal

The Win32:Qqhack-E [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Qqhack-E [PUP] virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32:Qqhack-E [PUP]?


File Info:

name: B732EFF156A3539D12CC.mlw
path: /opt/CAPEv2/storage/binaries/400a9f6458fdf56db036ce264956b1f18e5218b76adb818700550343c491641b
crc32: 9038C328
md5: b732eff156a3539d12ccd4dc5183bed4
sha1: 1204375ddecc193e9aaec026856f554356076b57
sha256: 400a9f6458fdf56db036ce264956b1f18e5218b76adb818700550343c491641b
sha512: 7c1ea9fafd935f8df94e63f5d3bd4ba82cd52a1bf8ad90af4724e5403ef6a02bcffef8974fa5ce07cc06a9ca500cb1db717324ddb341553a883fbb4670346b90
ssdeep: 12288:/3BpxsZMhfy1MSR2qGgC527N99NkDlEFXUnXjPfNWRR78TH:/RPsZMtVSpGL5ON97keijPfNA87
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F8554A02A643C4B0D2961EB00B97B77558785E253D21DB8B9BB0FD6C9F321A17E2F19C
sha3_384: e29de112722464a478cc59619e7754e756049aeeb634986b2dedbb16514d74ff5f5cec772a057540151aa9b1bd9a247a
ep_bytes: e829810000e916feffffc3b8a72f4900
timestamp: 2013-04-17 12:48:49

Version Info:

0: [No Data]

Win32:Qqhack-E [PUP] also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Qqhack.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.b732eff156a3539d
SkyhighBehavesLike.Win32.Trojan.tm
Cylanceunsafe
SangforTrojan.Win32.Agent.Vry3
AlibabaTrojan:Win32/Qqhack.eff6acaf
Cybereasonmalicious.ddecc1
BitDefenderThetaGen:NN.ZexaF.36608.prZ@auYp7Xo
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Tool.Qqhack-9919543-0
AvastWin32:Qqhack-E [PUP]
F-SecureTrojan.TR/Crypt.XPACK.Gen7
Trapminemalicious.moderate.ml.score
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Generic.aijd
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Win32.FlyStudio.a
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.17LR02M
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R625194
McAfeeArtemis!B732EFF156A3
MalwarebytesGeneric.Malware.AI.DDS
RisingTrojan.Generic@AI.100 (RDML:ruBCLWLZWwtlE59wwfRO1g)
YandexTrojan.GenAsa!1brNDXO/QaM
IkarusTrojan.Win32
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AP.9FE8F!tr
AVGWin32:Qqhack-E [PUP]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32:Qqhack-E [PUP]?

Win32:Qqhack-E [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment