Trojan

Trojan.Downloader.JQMW removal tips

Malware Removal

The Trojan.Downloader.JQMW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Downloader.JQMW virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan.Downloader.JQMW?


File Info:

name: EFE4C213C4897AC810D7.mlw
path: /opt/CAPEv2/storage/binaries/e1a131ed57711385170986b9145dfe6383dc7abf5012ce6d6bc36b7b52e2971b
crc32: E541F28B
md5: efe4c213c4897ac810d730fac1f2cff4
sha1: 8a7af73f39fe41289ebda5b8c7919a765ec2e906
sha256: e1a131ed57711385170986b9145dfe6383dc7abf5012ce6d6bc36b7b52e2971b
sha512: 1fe505c41d2e206fdfb8efb6cd8e35587cc7ad440c214d2f4637f99938803419235f49bfa98108fb37b017088b217e4d518e58340bc58aeab6aca9c4673e0d1d
ssdeep: 768:ThjrhoahHKVxvmgtxypOd/22fZ3SSPsED3VK2+ZtyOjgO4r9vFAg2rqzUkJ:TtrhXFf6ypOd/22fZ3lYTjipvF2KvJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D7432821B7C190B1E4A702318476C9F1523BBD96BCB1422F3E99374EA8B2A958C55F1F
sha3_384: 4e0463cfeeb7aa29849b0ab9b8b29d992b9b23097eb4b0e514a80f1514b544a05bd776589e3582136c6c3e223c8ab285
ep_bytes: 558bec6aff684030400068001b400064
timestamp: 2014-03-31 19:24:37

Version Info:

0: [No Data]

Trojan.Downloader.JQMW also known as:

BkavW32.FamVT.GeND.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Downloader.JQMW
FireEyeGeneric.mg.efe4c213c4897ac8
CAT-QuickHealTrojanPWS.Zbot.Gen
ALYacTrojan.Downloader.JQMW
CylanceUnsafe
ZillyaDropper.Injector.Win32.61232
K7AntiVirusTrojan-Downloader ( 004941701 )
K7GWTrojan-Downloader ( 004941701 )
Cybereasonmalicious.3c4897
CyrenW32/Trojan.GWMH-3336
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Waski.B
APEXMalicious
ClamAVWin.Downloader.Upatre-5744087-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Downloader.JQMW
NANO-AntivirusTrojan.Win32.Crypted.cwaqgb
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b8c426
Ad-AwareTrojan.Downloader.JQMW
SophosML/PE-A + Mal/Zbot-PY
ComodoTrojWare.Win32.Injector.KCF@59nxkk
DrWebTrojan.DownLoader9.53400
VIPRETrojan.Win32.Generic.pak!cobra
EmsisoftTrojan.Downloader.JQMW (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Injector.AI
JiangminTrojanDropper.Injector.avne
AviraTR/MSIL.Injector.kbcq
Antiy-AVLTrojan/Generic.ASMalwS.954313
MicrosoftTrojanDownloader:Win32/Upatre.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R103174
Acronissuspicious
McAfeeTrojan-FDYB!EFE4C213C489
MAXmalware (ai score=88)
VBA32TrojanDropper.Injector
MalwarebytesMalware.AI.2235937286
TrendMicro-HouseCallTROJ_UPATRE.SMN7
RisingTrojan.Generic@ML.98 (RDML:tX5NCntTQZpz2hM2OZrWhg)
YandexTrojan.DR.Injector!i/OD2JI8k1M
IkarusVirus.Win32.Vundo
MaxSecureTrojan.Upatre.Gen
FortinetW32/Bublik.TT!tr
BitDefenderThetaGen:NN.ZexaF.34294.dqY@a0zSinci
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Trojan.Downloader.JQMW?

Trojan.Downloader.JQMW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment