Trojan

Trojan.Downloader.JQBY removal

Malware Removal

The Trojan.Downloader.JQBY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Downloader.JQBY virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • CAPE detected the embedded win api malware family
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Downloader.JQBY?


File Info:

name: BC1007D85ED334BEFB96.mlw
path: /opt/CAPEv2/storage/binaries/5aee01fa44e09d7d3ddbaa92bea053cb6fa596ea9a4092434cdd3d737b30720a
crc32: 9AD30A3A
md5: bc1007d85ed334befb960a6fe154166f
sha1: 60da88fc3504b164adfee5f99ae98a6b8706bda7
sha256: 5aee01fa44e09d7d3ddbaa92bea053cb6fa596ea9a4092434cdd3d737b30720a
sha512: 249abeace63f2826b912c6e4a3bfd6f215667278b51c3c1327865e97ad6428c78f7188fb5220a05865ad815b5e411425d528ab6bd289e4f26da2a1607e8e0e6a
ssdeep: 768:bFPm5zusFUB2preAr+Ofjg0S16avdrQFiLjJvtX3:bFPmpiif/oc+vX3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T146E26138AAD82573D3B7CAB595F691C3B834B8223E15480E54CB23890D33F57BD9261E
sha3_384: e7a5cfb3faf021f4bb37ac4f10e3efa5886eff34e2f7572a4a6fcfa034308c05d238be98e19357685bd396378adcfa7b
ep_bytes: 60be008000088dbe0090ffff5783cdff
timestamp: 2012-02-16 02:43:56

Version Info:

0: [No Data]

Trojan.Downloader.JQBY also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.bc1007d85ed334be
SkyhighBehavesLike.Win32.PWSZbot.nm
McAfeeArtemis!BC1007D85ED3
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDownloader.Upatre.Win32.80673
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055c6c71 )
AlibabaTrojanDownloader:Win32/Upatre.2ed6ebbe
K7GWTrojan-Downloader ( 0055c6c71 )
BaiduWin32.Trojan-Downloader.Small.c
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Small.AAB
APEXMalicious
AvastWin32:Evo-gen [Trj]
ClamAVWin.Trojan.Zbot-64721
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.pef
BitDefenderTrojan.Downloader.JQBY
NANO-AntivirusTrojan.Win32.Bublik.cjdxct
MicroWorld-eScanTrojan.Downloader.JQBY
TencentTrojan-Downloader.Win32.Waski.16000151
SophosTroj/Zbot-GNC
F-SecureTrojan.TR/Crypt.ULPM.Gen2
DrWebTrojan.DownLoad3.28161
VIPRETrojan.Downloader.JQBY
Trapminesuspicious.low.ml.score
EmsisoftTrojan.Downloader.JQBY (B)
Paloaltogeneric.ml
JiangminTrojan/Generic.bcdos
GoogleDetected
AviraTR/Crypt.ULPM.Gen2
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.b.989
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.MAUA@5rueuc
ArcabitTrojan.Downloader.JQBY
ViRobotTrojan.Win32.Zbot.25088.B[UPX]
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.pef
GDataWin32.Trojan-Downloader.Upatre.BJ
VaristW32/Trojan.LDYT-3789
AhnLab-V3Trojan/Win32.Upatre.C3069854
Acronissuspicious
VBA32Trojan.Bublik
ALYacTrojan.Downloader.JQBY
Cylanceunsafe
PandaTrj/Genetic.gen
RisingMalware.FakePDF/ICON!1.9C28 (CLASSIC)
YandexTrojan.GenAsa!0NHD56KEAmA
IkarusBackdoor.Win32.Androm
MaxSecureTrojan.Upatre.Gen
FortinetW32/Bublik.AEBW!tr
BitDefenderThetaGen:NN.ZexaF.36804.cmMfaenX5kli
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/Zbot.FF8PHU

How to remove Trojan.Downloader.JQBY?

Trojan.Downloader.JQBY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment