Trojan

About “Dropped:Trojan.Downloader.JQJR” infection

Malware Removal

The Dropped:Trojan.Downloader.JQJR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Trojan.Downloader.JQJR virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings

Related domains:

wpad.local-net
ddos.dnsnb8.net

How to determine Dropped:Trojan.Downloader.JQJR?


File Info:

name: EC5270C70B35E6E02A59.mlw
path: /opt/CAPEv2/storage/binaries/4b876fdaaa88183669c52d1987edefbbd1bb6b640a3fda8a825924b4240c0970
crc32: A9E2F1F5
md5: ec5270c70b35e6e02a593cdb6405fe88
sha1: 2a2cb147d23c998f9304e9913cd41d6321c6bc79
sha256: 4b876fdaaa88183669c52d1987edefbbd1bb6b640a3fda8a825924b4240c0970
sha512: 75e0a81c526ecd5cc8d5237a78a445d56838daaed71bed1bbd4fbd93d7e9453646fefc9bc139377b9ad7e04d7edbc082d3f7ce9eceb33bc395f8c824ae65120a
ssdeep: 12288:r14Yavl7hopQHi/5OLYxdFWebuK7koG3K/VblQcBMNy6TK:h4Y2FOp/5OLYxdgebl9CcBMIp
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16EB412428A10D056FBA847721603F9D1091BAC7D04E6F26EF579BD3C3E715D34AA38AE
sha3_384: f64fc4fdc5309c3a931e87a2c39690111b89e96de413a6bea1c1a4bba8efd3bf73a82fa1179822a02f58cba2a9dc8124
ep_bytes: 60be00204e008dbe00f0f1ff5783cdff
timestamp: 2021-09-14 15:06:35

Version Info:

CompanyName: 溜云库
FileDescription: 文件更新工具
FileVersion: 1.0.0.26
InternalName: 文件更新工具
LegalCopyright: Copyright (C) Maple 2021
OriginalFilename: CopyFiles.exe
ProductName: 文件更新工具
ProductVersion: 1.0.0.26
Translation: 0x0009 0x04b0

Dropped:Trojan.Downloader.JQJR also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacDropped:Trojan.Downloader.JQJR
CylanceUnsafe
ZillyaVirus.Nimnul.Win32.5
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 0040f7441 )
K7GWVirus ( 0040f7441 )
CyrenW32/PatchLoad.E
SymantecW32.Wapomi.C!inf
ESET-NOD32a variant of Win32/Packed.AAuto.B suspicious
APEXMalicious
ClamAVWin.Malware.Aauto-9839278-0
KasperskyVirus.Win32.Nimnul.f
BitDefenderDropped:Trojan.Downloader.JQJR
NANO-AntivirusTrojan.Win32.Banload.cstqaj
MicroWorld-eScanDropped:Trojan.Downloader.JQJR
AvastWin32:Evo-gen [Susp]
TencentVirus.Win32.Loader.aab
Ad-AwareDropped:Trojan.Downloader.JQJR
SophosW32/Nimnul-C
ComodoVirus.Win32.Wali.KA@558nxg
DrWebBackDoor.Darkshell.246
VIPRETrojan-Downloader.Win32.Small
TrendMicroPE_WAPOMI.BM
FireEyeDropped:Trojan.Downloader.JQJR
EmsisoftDropped:Trojan.Downloader.JQJR (B)
IkarusTrojan-Downloader.Win32.Small
GDataWin32.Virus.Wapomi.A
JiangminWin32/Nimnul.f
AviraW32/Jadtre.D
Antiy-AVLTrojan/Generic.ASVirus.14D
ArcabitTrojan.Downloader.JQJR
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
TACHYONVirus/W32.Ramnit.C
AhnLab-V3Win32/VJadtre.Gen
MAXmalware (ai score=87)
VBA32TrojanDownloader.Banload
TrendMicro-HouseCallPE_WAPOMI.BM
RisingVirus.Roue!1.9E10 (CLASSIC)
YandexTrojan.GenAsa!uDgyVfKmTBk
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/CoinMiner.EC2B!tr
BitDefenderThetaAI:Packer.2A02B3BB20
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.70b35e
PandaW32/Pcarrier.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Dropped:Trojan.Downloader.JQJR?

Dropped:Trojan.Downloader.JQJR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment