Worm

Worm.Win32.Qvod.pla removal guide

Malware Removal

The Worm.Win32.Qvod.pla is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Qvod.pla virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Worm.Win32.Qvod.pla?


File Info:

name: CEDC7C1A53710D97906D.mlw
path: /opt/CAPEv2/storage/binaries/6887bcd4aa70234262174d2fc709dd68fc79aa8651ef99c65dfe8ce1607e7da7
crc32: 6DA237F9
md5: cedc7c1a53710d97906d3f7974d38c1d
sha1: c9915f7404ee3036e75676ccba3c927a5590fd33
sha256: 6887bcd4aa70234262174d2fc709dd68fc79aa8651ef99c65dfe8ce1607e7da7
sha512: 8297d52a02713f0057c21f840ad20e434ea53de60607b1cafe70555ccdd096520cc691ed93eafaaf6805ca94844c9bfd2511a1396f83ba7ffb7ccde92fcf3edd
ssdeep: 1536:3K7N7e5HvCHs/4h41xG5q2a5cgI2URTwn45W59HkzeLYPL3fVynafqvPdIOU5gFM:3KBC5CH+xUEcgI7w95YeoLoSqtIzFj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15D93029038D878A2E7EECB3650305F4451288E5DC9B4A56E1C487EA53FFE78614E3EA1
sha3_384: 578aa83a8cb832de087a6221da31e58ef83b0d6ea8a71e896dc7f2848654d9e13dd5f6b4d933b447d9297357859f59d6
ep_bytes: b80030420068a9f0400064ff35000000
timestamp: 2010-07-12 14:04:33

Version Info:

CompanyName: Shenzhen QVOD Technology Co.,Ltd
FileDescription: QvodInstall Module
FileVersion: 3, 0, 0, 0
InternalName: QvodInstall.exe
LegalCopyright: Copyright(C) 2006-2009 QVOD
OriginalFilename: QvodInstall.exe
ProductName: QvodInstall Module
ProductVersion: 3, 0, 0, 0
Translation: 0x0409 0x04b0

Worm.Win32.Qvod.pla also known as:

BkavW32.AIDetect.malware2
LionicWorm.Win32.Qvod.tp0c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Win32.QVod.A
CAT-QuickHealExploit.ShellCode.Gen
ALYacGen:Win32.QVod.A
CylanceUnsafe
SangforVirus.Win32.Wapomi.K
K7AntiVirusTrojan ( 0055e40b1 )
AlibabaWorm:Win32/ShellCode.bfdb79ec
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Trojan.KillAV.c
VirITTrojan.Win32.Generic.BUNL
CyrenW32/Pikorms.A.gen!Eldorado
SymantecW32.Wapomi.B
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Wapomi.K
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Wapomi-9882043-0
KasperskyWorm.Win32.Qvod.pla
BitDefenderGen:Win32.QVod.A
NANO-AntivirusTrojan.Win32.Agent.boohc
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastWin32:AutoRun-CTB [Trj]
TencentTrojan.Win32.Qvod.aw
Ad-AwareGen:Win32.QVod.A
SophosMal/Generic-R + Mal/Emogen-Y
ComodoBackdoor.Win32.Qvod.~IC@1vk6eh
DrWebTrojan.Siggen6.4443
ZillyaWorm.Qvod.Win32.1044
TrendMicroPE_PIKORAV.SM-O
McAfee-GW-EditionBehavesLike.Win32.Generic.nc
FireEyeGeneric.mg.cedc7c1a53710d97
EmsisoftGen:Win32.QVod.A (B)
SentinelOneStatic AI – Malicious PE
JiangminWorm/Qvod.x
WebrootW32.Rogue.Gen
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
KingsoftWin32.MalWare.Heur_Generic.c.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitGen:Win32.QVod.A
ZoneAlarmWorm.Win32.Qvod.pla
GDataGen:Win32.QVod.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Qvod.R2044
McAfeeGeneric Dropper.uk
VBA32BScope.Trojan.SvcHorse.01643
MalwarebytesNimnul.Virus.FileInfector.DDS
ZonerProbably Heur.ExeHeaderP
TrendMicro-HouseCallPE_PIKORAV.SM-O
RisingWorm.Qvod!1.9926 (CLOUD)
YandexTrojan.GenAsa!udikpZMm8lk
IkarusWorm.Win32.Pikorms
MaxSecureTrojan.Malware.9742509.susgen
FortinetW32/Generic.AC.7131B!tr
BitDefenderThetaGen:NN.ZexaF.34638.fqueaO97YVdb
AVGWin32:AutoRun-CTB [Trj]
Cybereasonmalicious.a53710
PandaTrj/Genetic.gen

How to remove Worm.Win32.Qvod.pla?

Worm.Win32.Qvod.pla removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment