Trojan

How to remove “MemScan:Trojan.Downloader.JQDW”?

Malware Removal

The MemScan:Trojan.Downloader.JQDW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MemScan:Trojan.Downloader.JQDW virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine MemScan:Trojan.Downloader.JQDW?


File Info:

name: 27EA6A1F9A1193B8AF65.mlw
path: /opt/CAPEv2/storage/binaries/10837d45afec9298a7782552526b33e31d69e669729cd05f24817c23074e3745
crc32: 267951FE
md5: 27ea6a1f9a1193b8af655f83568ffb8f
sha1: 3de54354323bc5bf51f88b18823ad102c4897d4d
sha256: 10837d45afec9298a7782552526b33e31d69e669729cd05f24817c23074e3745
sha512: 424d07ea5b81f38820926792bbbaacb939c6dbd05733a4eff7aaee019c8a0b78cc65263cf3bd5fe6a22508fc8b2b039edc9306f5586d8432abfc67719f266a94
ssdeep: 96:dyeIFiRWKFOxlSPlXL7luHnnwR2Us2CXZLuK:dNMiRWKnP1onwR2FzZLL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BAB2B44BA7ED0D7EE3F38974C8B2C0432DB1B033551366AD159402C53D62AA5C971F91
sha3_384: 60fe02bb6e0702d0f9b73fd79cab9a87cb100208b0d098aa04649f4cc42d2273959d979c1521697f314cab976cc27299
ep_bytes: 609c68216767656821676765e8000000
timestamp: 2013-10-30 10:58:20

Version Info:

0: [No Data]

MemScan:Trojan.Downloader.JQDW also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanMemScan:Trojan.Downloader.JQDW
FireEyeGeneric.mg.27ea6a1f9a1193b8
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacMemScan:Trojan.Downloader.JQDW
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0048f6391 )
BitDefenderMemScan:Trojan.Downloader.JQDW
K7GWTrojan-Downloader ( 0048f6391 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Downloader.JQDW
VirITTrojan.Win32.DownLoad3.BPRD
CyrenW32/S-b8568f35!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
RisingDownloader.Upatre!8.B5 (TFE:5:oIHg3KtuxL)
SophosMal/EggBang-A
F-SecureTrojan.TR/AD.Yarwi.hanuq
DrWebTrojan.DownLoad3.28161
VIPREMemScan:Trojan.Downloader.JQDW
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionGenericRXUB-BS!8FBD031B7911
Trapminemalicious.moderate.ml.score
EmsisoftMemScan:Trojan.Downloader.JQDW (B)
IkarusTrojan-Downloader.Win32.Waski
JiangminTrojan.Generic.hgmzg
AviraTR/AD.Yarwi.hanuq
Antiy-AVLTrojan/Win32.Waski.a
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.A@52i1eo
MicrosoftTrojan:Win32/Upatre.MB!MTB
ZoneAlarmVHO:Trojan-Downloader.Win32.Convagent.gen
GDataMemScan:Trojan.Downloader.JQDW
GoogleDetected
AhnLab-V3Trojan/Win32.Dloader.R87521
McAfeeGenericRXAA-FA!27EA6A1F9A11
MAXmalware (ai score=88)
DeepInstinctMALICIOUS
VBA32Trojan.Download
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
TencentTrojan-Downloader.Win32.Small.16000133
YandexTrojan.GenAsa!xjw/xZS1BKE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Kryptik.CP!tr
BitDefenderThetaAI:Packer.093765FB1F
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.4323bc
AvastWin32:Evo-gen [Trj]

How to remove MemScan:Trojan.Downloader.JQDW?

MemScan:Trojan.Downloader.JQDW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment