Trojan

How to remove “Trojan.Downloader.QQ”?

Malware Removal

The Trojan.Downloader.QQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Downloader.QQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity contains more than one unique useragent.
  • Uses suspicious command line tools or Windows utilities

Related domains:

cdn.boluobl.cn
AndyHarrison-PC
wpad
apps.game.qq.com
map.baidu.com
cdn.putaopt.cn
z8.cnzz.com

How to determine Trojan.Downloader.QQ?


File Info:

crc32: 78AA897B
md5: 342f918d70febe042028c3d26eb9192d
name: flashupdata_setup.exe
sha1: a71150669cba4b4cece5d3991cea084b53ebe0ee
sha256: 697d33be52a77659f0347fe0f001449b40d42497a14069a42fcb66ba8d1dedac
sha512: 4d557a5a9ef0b8d63e5ec7a06e169bfb171fefb63c43401636a518fbf428b78338faa728078d1324f727b7f659ac5917570e684094f8eae4edd1c8b77bc7f466
ssdeep: 6144:a1+2L2HBLRPkI311RKqnxw/xfvOffirbjYnKYanmiRUB:a1pgRPf1Rtw/x+far/YKYSmsU
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

LegalCopyright: Copyright (C) 2019
FileVersion: 19, 10, 12, 2
ProductVersion: 19, 10, 12, 2
Translation: 0x0804 0x04b0

Trojan.Downloader.QQ also known as:

DrWebTrojan.Siggen8.63714
MicroWorld-eScanGen:Variant.Graftor.494706
FireEyeGeneric.mg.342f918d70febe04
CAT-QuickHealBackdoor.Gulpix
ALYacGen:Variant.Graftor.494706
MalwarebytesTrojan.Downloader.QQ
VIPRETrojan-Spy.Win32.Zbot.gen (v)
AegisLabTrojan.Win32.Graftor.4!c
SangforMalware
K7AntiVirusTrojan ( 00523b141 )
BitDefenderGen:Variant.Graftor.494706
K7GWTrojan ( 00523b141 )
Cybereasonmalicious.d70feb
TrendMicroTROJ_GEN.R002C0PLK19
BitDefenderThetaGen:NN.ZexaF.34100.sm0faCF7ascj
F-ProtW32/Graftor.FI.gen!Eldorado
APEXMalicious
Paloaltogeneric.ml
GDataGen:Variant.Graftor.494706
KasperskyHEUR:Backdoor.Win32.Gulpix.vho
AlibabaBackdoor:Win32/Tiggre.72c607ca
NANO-AntivirusTrojan.Win32.Graftor.gmkxrh
ViRobotTrojan.Win32.Z.Graftor.297984.A
AvastWin32:Trojan-gen
TencentWin32.Trojan.Graftor.Lhdn
Ad-AwareGen:Variant.Graftor.494706
SophosMal/Behav-010
ComodoMalware@#g27412l68u6n
F-SecureHeuristic.HEUR/AGEN.1044618
ZillyaTrojan.Agent.Win32.1224492
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Gupboot.dc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Graftor.494706 (B)
CyrenW32/Graftor.FI.gen!Eldorado
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1044618
Antiy-AVLTrojan[Backdoor]/Win32.Gulpix
Endgamemalicious (high confidence)
ArcabitTrojan.Graftor.D78C72
ZoneAlarmHEUR:Backdoor.Win32.Gulpix.vho
MicrosoftTrojan:Win32/Tiggre!rfn
AhnLab-V3Trojan/Win32.Agent.C3143770
Acronissuspicious
McAfeeArtemis!342F918D70FE
MAXmalware (ai score=100)
VBA32BScope.Trojan.Tiggre
CylanceUnsafe
ESET-NOD32a variant of Win32/Agent.ZJL
TrendMicro-HouseCallTROJ_GEN.R002C0PLK19
RisingBackdoor.Gulpix!8.3DA (CLOUD)
YandexBackdoor.Gulpix!FLYqSMs6jEY
IkarusBackdoor.Win32.Zegost
eGambitUnsafe.AI_Score_98%
FortinetW32/Agent.ZJL!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360HEUR/QVM17.0.CE1F.Malware.Gen

How to remove Trojan.Downloader.QQ?

Trojan.Downloader.QQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment