Trojan

Trojan.Downloader.JQLC removal

Malware Removal

The Trojan.Downloader.JQLC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Downloader.JQLC virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan.Downloader.JQLC?


File Info:

name: FCD0800CE8118BD97910.mlw
path: /opt/CAPEv2/storage/binaries/8b357cd3d8ddf4b723fb324ebe61101e7ecc95c592f484da54bbd6ed8cefc580
crc32: C073DE9C
md5: fcd0800ce8118bd979106d8b462f3187
sha1: fbb5d3ce59851839444bdec43c74bc25a686e81d
sha256: 8b357cd3d8ddf4b723fb324ebe61101e7ecc95c592f484da54bbd6ed8cefc580
sha512: ef295983707337cb47bb003691dc0600505b079a5f38bd86c4f6ff00f4b7f6b2d42ea9aa182b1c66232e50f906a68345f35f2aaf7959760141ff86eb544fbf1d
ssdeep: 192:5OO0T8i1FQwPLMLMCTSJqAYpUAf7AlC+EguEHTP3MwKj4uohUlQzY6d4slB1:EOZi1fLMLMnqAYpU0AC+5Yt4Qx6V
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T108F275757AE4A972D137857444F7F1D2B8ADBD613E1A780F2993B34C0973782B8A090E
sha3_384: 294d08c68e76e0e9b689b68045be6bd451234349419922d4e4424a3dadaf90756b0925c8af749833952ea6f7ef5655fd
ep_bytes: e8befbffffeb5733c0c35753508bd885
timestamp: 2005-08-23 23:17:05

Version Info:

0: [No Data]

Trojan.Downloader.JQLC also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Downloader.JQLC
FireEyeGeneric.mg.fcd0800ce8118bd9
ALYacTrojan.Downloader.JQLC
CylanceUnsafe
VIPRETrojan.Downloader.JQLC
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
K7GWTrojan ( 0052964f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan-Downloader.Waski.a
CyrenW32/S-546bcf37!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
ClamAVWin.Malware.Upatre-9794265-0
KasperskyHEUR:Trojan.Win32.Delf.gen
BitDefenderTrojan.Downloader.JQLC
NANO-AntivirusTrojan.Win32.Bublik.cunynf
AvastWin32:Agent-AUID [Trj]
TencentMalware.Win32.Gencirc.10b0c2d9
Ad-AwareTrojan.Downloader.JQLC
EmsisoftTrojan.Downloader.JQLC (B)
ComodoTrojWare.Win32.Upatre.O@58re0o
DrWebTrojan.DownLoad3.28161
ZillyaTrojan.Generic.Win32.699828
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.nz
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/Dorf-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.15QA5SK
JiangminTrojan.Generic.dbdav
GoogleDetected
AviraTR/Yarwi.AD.113
Antiy-AVLTrojan/Generic.ASMalwS.3CF7
ArcabitTrojan.Downloader.JQLC
ZoneAlarmHEUR:Trojan.Win32.Delf.gen
MicrosoftTrojanDownloader:Win32/Upatre.AA
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.C3109472
McAfeeGenericR-PBA!FCD0800CE811
MAXmalware (ai score=89)
VBA32BScope.TrojanSpy.Zbot
MalwarebytesTrojan.Upatre.Generic
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingSpyware.Zbot!8.16B (TFE:2:HS3wTMOjTdD)
IkarusTrojan-Downloader.Win32.Upatre
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
BitDefenderThetaGen:NN.ZexaF.34646.cqX@aqD!Jnfi
AVGWin32:Agent-AUID [Trj]
Cybereasonmalicious.ce8118

How to remove Trojan.Downloader.JQLC?

Trojan.Downloader.JQLC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment