Trojan

Trojan-Dropper.Win32.Phpw.qq removal guide

Malware Removal

The Trojan-Dropper.Win32.Phpw.qq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Phpw.qq virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan-Dropper.Win32.Phpw.qq?


File Info:

name: 6291897EC0743E62D9AE.mlw
path: /opt/CAPEv2/storage/binaries/b8036de6e3405263ec290ebb6e2700f59a50480ad9dcbe9d9be921284dbd93cd
crc32: F6ADF41A
md5: 6291897ec0743e62d9ae12571c5f7480
sha1: b74359505f8344080a8fd74e7726c030e4beead7
sha256: b8036de6e3405263ec290ebb6e2700f59a50480ad9dcbe9d9be921284dbd93cd
sha512: d11faec85fab0c071d7a26da3f580fedd2d74a92d78079e699a25ec31d3c4af5c503835c17e43ccdfdc5be78b46e58e593dc7e01f8a2e62b5a59b7c57bd89a6b
ssdeep: 49152:4TwrpjFGmJy95RlflFOA2nkJIibM/c1WfSRwqqshZOYSPn0QbhkY:4TypjFGmJy95RlfD2ncR4/c8fSn1V+0y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T107C522117AC0C0B7E96B053848A5A7BAAB7EFA310B609AD763440B2E1F713D1DE35357
sha3_384: 32ce56d7d15817d43d217309177571aae1a1f7cbda0ff4bd8b06776ce8efdd3bd1d960974bf21aac6e65951805e3c8c5
ep_bytes: e8b0050000e97afeffff558bec6a00ff
timestamp: 2021-12-03 06:14:35

Version Info:

0: [No Data]

Trojan-Dropper.Win32.Phpw.qq also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Phpw.b!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.RP.FwW@bi0VVciO
FireEyeGeneric.mg.6291897ec0743e62
ALYacGen:Trojan.Heur.RP.FwW@bi0VVciO
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaTrojanDropper:Win32/DLOADER.90be261f
K7GWBackdoor ( 00544de51 )
K7AntiVirusBackdoor ( 00544de51 )
CyrenW32/Trojan.LJIU-8614
ESET-NOD32a variant of Win32/Rbot.BKT
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Dropper.Win32.Phpw.qq
BitDefenderGen:Trojan.Heur.RP.FwW@bi0VVciO
NANO-AntivirusTrojan.Win32.FKM.fetkza
AvastWin32:Trojan-gen
RisingTrojan.Generic@ML.94 (RDML:GcgCdWwNrBZPHfA4mPt4xA)
Ad-AwareGen:Trojan.Heur.RP.FwW@bi0VVciO
DrWebWIN.WORM.Virus
TrendMicroTROJ_GEN.R002C0PL621
McAfee-GW-EditionBehavesLike.Win32.Rootkit.vc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Heur.RP.FwW@bi0VVciO
JiangminTrojanDropper.Phpw.jv
AviraTR/Agent.qmxcw
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Heur.RP.E513D6
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.RK.C4678090
MAXmalware (ai score=87)
VBA32TrojanDropper.Phpw
MalwarebytesTrojan.Dropper
TencentMalware.Win32.Gencirc.11da3880
YandexTrojan.Agent!/BiT9vW9vU4
IkarusTrojan.Win32.Agent
eGambitUnsafe.AI_Score_99%
FortinetW32/Rbot.BKT!tr
BitDefenderThetaAI:Packer.EE48D6711F
AVGWin32:Trojan-gen
PandaTrj/CI.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-Dropper.Win32.Phpw.qq?

Trojan-Dropper.Win32.Phpw.qq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment