Trojan

Should I remove “Trojan.Downloader.JQIJ”?

Malware Removal

The Trojan.Downloader.JQIJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Downloader.JQIJ virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan.Downloader.JQIJ?


File Info:

name: A1321E37C0C3F008102E.mlw
path: /opt/CAPEv2/storage/binaries/5344124ba1d0101e31721921a5f1803edc734bf429f17b5226d4621b229313e6
crc32: 9240C515
md5: a1321e37c0c3f008102ece470be7e9de
sha1: c50635c537b260d241e7e8a8a88b2680e44ec858
sha256: 5344124ba1d0101e31721921a5f1803edc734bf429f17b5226d4621b229313e6
sha512: a26f78cebbec6c3736155115fd9b5502310ef6964cf08deb8e26c6b6d055258e39f6e81ac7837726c8ea0c964929ad760f5da43d2e0d072f0b0e870f5f158fd6
ssdeep: 192:62cDDbjheWn1kaQgFX8SfBDWemZmpIqz0oxHZq3Gi9wnV:6HLj80kaKSZDWpqIox5q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15BB238F29B20E933D7A246314E7BB33153D4B5DF1B9A96331DD1196DF0AB683881B142
sha3_384: 61ed1a6888042c25d872dcd1c5b9f56a9bfb9345d600f2d9953b945541c5ca7e8dbb08857ee15597ca91604e11cbb515
ep_bytes: 558bec83ec546a00ff1504304000ff15
timestamp: 2014-01-20 07:46:21

Version Info:

0: [No Data]

Trojan.Downloader.JQIJ also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanTrojan.Downloader.JQIJ
FireEyeGeneric.mg.a1321e37c0c3f008
CAT-QuickHealTrojanDownloader.Upatre.A4
McAfeeDownloader-FZX!A1321E37C0C3
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0050357f1 )
BitDefenderTrojan.Downloader.JQIJ
K7GWTrojan ( 0050357f1 )
Cybereasonmalicious.7c0c3f
BaiduWin32.Trojan-Downloader.Waski.a
CyrenW32/Trojan.CEQV-3204
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
KasperskyUDS:Trojan.Win32.Tremp.gen
NANO-AntivirusTrojan.Win32.Agent.cstemo
RisingTrojan.DL.Win32.Upatre.aku (CLASSIC)
Ad-AwareTrojan.Downloader.JQIJ
SophosML/PE-A + Troj/Zbot-HPZ
ComodoTrojWare.Win32.Yarwi.BV@56uh49
DrWebTrojan.DownLoad3.28161
TrendMicroTROJ_UPATRE.SMBX
McAfee-GW-EditionDownloader-FZX!A1321E37C0C3
EmsisoftTrojan.Downloader.JQIJ (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Agent.emov
Webroot
AviraTR/Crypt.XPACK.Gen5
MicrosoftTrojanDownloader:Win32/Upatre.AA
SUPERAntiSpywareTrojan.Agent/Gen-Upatre
ZoneAlarmUDS:Trojan.Win32.Tremp.gen
GDataTrojan.Downloader.JQIJ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Waski.C252209
BitDefenderThetaGen:NN.ZexaF.34712.bmW@aKkRg3ci
ALYacTrojan.Downloader.JQIJ
MAXmalware (ai score=84)
VBA32Trojan.Bublik
MalwarebytesSpyware.Zbot
PandaGeneric Malware
TrendMicro-HouseCallTROJ_UPATRE.SMBX
TencentTrojan.Win32.Downloader.wc
IkarusTrojan-Downloader.Win32.Upatre
FortinetW32/Waski.A!tr
AVGWin32:Agent-AUID [Trj]
AvastWin32:Agent-AUID [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Downloader.JQIJ?

Trojan.Downloader.JQIJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment