Home Malware Programs Trojans PWS:Win32/QQpass.GG

PWS:Win32/QQpass.GG

Posted: September 6, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 52
First Seen: September 6, 2013
Last Seen: December 30, 2022
OS(es) Affected: Windows

PWS:Win32/QQpass.GG is a Trojan that is specifically used to grab personal information from victims, such as user names and passwords, and then transfer that information to a remote attacker. Once installed on the corrupted PC, PWS:Win32/QQpass.GG makes system changes by creating the potentially malicious files on an infected computer system. PWS:Win32/QQpass.GG may contact the certain remote hosts for the aim to report a new infection to its author, to confirm Internet connectivity, to download and run arbitrary files (involving updates or additional malware threats), to receive configuration or other data, to upload data taken from the attacked PC, to receive instructions from a remote attacker.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



[system folder]\gggame.db File name: [system folder]\gggame.db
Mime Type: unknown/db
Group: Malware file
C:\Documents and Settings\<username>\local settings\temp\z1.exe File name: C:\Documents and Settings\<username>\local settings\temp\z1.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\Documents and Settings\<username>\local settings\temp\dnfbox89.exe File name: C:\Documents and Settings\<username>\local settings\temp\dnfbox89.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\Documents and Settings\<username>\local settings\temp\10c8718f.bat File name: C:\Documents and Settings\<username>\local settings\temp\10c8718f.bat
File type: Batch file
Mime Type: unknown/bat
Group: Malware file
C:\Documents and Settings\<username>\local settings\temp\nmue34d72378.exe File name: C:\Documents and Settings\<username>\local settings\temp\nmue34d72378.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\Documents and Settings\<username>\local settings\temp\exp_t2316.exe File name: C:\Documents and Settings\<username>\local settings\temp\exp_t2316.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\Documents and Settings\<username>\local settings\temp\_ir_sf_temp_0\irimg2.jpg File name: C:\Documents and Settings\<username>\local settings\temp\_ir_sf_temp_0\irimg2.jpg
Mime Type: unknown/jpg
Group: Malware file
C:\Documents and Settings\<username>\local settings\temp\_ir_sf_temp_0\irimg1.jpg File name: C:\Documents and Settings\<username>\local settings\temp\_ir_sf_temp_0\irimg1.jpg
Mime Type: unknown/jpg
Group: Malware file
C:\Documents and Settings\<username>\local settings\temp\_ir_sf_temp_0\lua5.1.dll File name: C:\Documents and Settings\<username>\local settings\temp\_ir_sf_temp_0\lua5.1.dll
Mime Type: unknown/dll
Group: Malware file
C:\Documents and Settings\<username>\local settings\temp\_ir_sf_temp_0\irsetup.exe File name: C:\Documents and Settings\<username>\local settings\temp\_ir_sf_temp_0\irsetup.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\Documents and Settings\<username>\local settings\temp\_ir_sf_temp_0\irsetup.dat File name: C:\Documents and Settings\<username>\local settings\temp\_ir_sf_temp_0\irsetup.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file

Additional Information

The following URL's were detected:
183.60.203.62ws617d3.CHEKFILES.COM
Loading...