Analysis by: Roland Marco Dela Paz

ALIASES:

Microsoft : Backdoor:Win32/Qakbot.gen!A; Kaspersky : Trojan-PSW.Win32.Qbot.pk

 PLATFORM:

Windows 2000, XP, Server 2003

 OVERALL RISK RATING:
 REPORTED INFECTION:
 SYSTEM IMPACT RATING:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted: Yes

  • In the wild: Yes

  OVERVIEW

This Trojan arrives as a file that exports the functions of other malware/grayware. It may be dropped by other malware.

It requires its main component to successfully perform its intended routine.

  TECHNICAL DETAILS

File Size: Varies
Memory Resident: Yes
Initial Samples Received Date: 12 Nov 2010

Arrival Details

This Trojan arrives as a file that exports the functions of other malware/grayware.

It may be dropped by the following malware:

Other Details

This Trojan requires its main component to successfully perform its intended routine.

  SOLUTION

Minimum Scan Engine: 8.900
VSAPI OPR PATTERN File: 7.617.00
VSAPI OPR PATTERN Date: 12 Nov 2010

Step 1

For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you disable System Restore to allow full scanning of your computer.

Step 2

Remove malware files dropped/downloaded by TSPY_QBOT.N

Step 3

Scan your computer with your live casino online product and note files detected as TSPY_QBOT.N

Step 4

Restart in Safe Mode

[ Learn More ]

Step 5

Search and delete the file detected as TSPY_QBOT.N

[ Learn More ]
Please make sure you check the Search Hidden Files and Folders checkbox in the More advanced options option to include all hidden files in the search result.