Trojan

Trojan.Loader.DQ malicious file

Malware Removal

The Trojan.Loader.DQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Loader.DQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Checks for the presence of known windows from debuggers and forensic tools
  • Attempts to identify installed analysis tools by registry key
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.Loader.DQ?


File Info:

name: AB6B8BBC9A21F63C2EB0.mlw
path: /opt/CAPEv2/storage/binaries/3d2ce7eaab252997f620d107b4df363b3bedb6c2e65ca903985d74b472b222f8
crc32: DEEB9E7C
md5: ab6b8bbc9a21f63c2eb0a06b10a1991a
sha1: 0bfed2e54ebacf7ee3392c978fa2bc833c21e3bc
sha256: 3d2ce7eaab252997f620d107b4df363b3bedb6c2e65ca903985d74b472b222f8
sha512: 2155518114f3e6a9c1339c0ade9213d6b0b2bc89cea9639bac2c13040e9cbdc7c600544e760e8876f31cd830ccce671b93009f4e753a5b2b8ba6ae70c652e459
ssdeep: 24576:tIEvKVe794+v5XCtjka+61PakIusnpqaO:zSk18N
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F165120EE973B68DED2145FE020544D24F3A6D305D72E01638D1BF2EA0FA5A74E4576B
sha3_384: ea55570135fa0f1d5b757a03079ff0dfdff2d1728ad0bcf5cd2b638de7640172d54f66c84d481bc12e5fc605b809bb7c
ep_bytes: 558bec81ec100100006a006a00ff1524
timestamp: 2012-03-25 06:42:35

Version Info:

0: [No Data]

Trojan.Loader.DQ also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Ticno.201
MicroWorld-eScanTrojan.Loader.DQ
CAT-QuickHealRansom.Foreign.19970
ALYacTrojan.Loader.DQ
CylanceUnsafe
VIPRETrojan.Loader.DQ
SangforTrojan.Win32.Save.a
Cybereasonmalicious.c9a21f
BitDefenderThetaAI:Packer.E3AC5B2E1F
VirITTrojan.Win32.Ticno.HT
CyrenW32/Ransom.BF.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32Win32/Multibar.EA potentially unwanted
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Loader.DQ
NANO-AntivirusTrojan.Win32.RiskGen.drglxm
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10b32ed3
Ad-AwareTrojan.Loader.DQ
EmsisoftTrojan.Loader.DQ (B)
ComodoMalCrypt.Indus!@1qrzi1
ZillyaTrojan.Foreign.Win32.51762
McAfee-GW-EditionBehavesLike.Win32.Trojan.tz
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.ab6b8bbc9a21f63c
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Loader.DQ
JiangminTrojan/Foreign.aakw
WebrootW32.Trojan.Loader
GoogleDetected
AviraHEUR/AGEN.1223527
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.3E7
MicrosoftProgram:Win32/Wacapew.C!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C889839
Acronissuspicious
McAfeeArtemis!AB6B8BBC9A21
VBA32Hoax.Foreign
MalwarebytesMalware.Heuristic.1001
RisingPUF.Vigua!8.10186 (TFE:1:YMZxMmNPhQN)
YandexTrojan.Foreign!RN0vGXHL574
IkarusPUA.Multibar
MaxSecureTrojan.Malware.8305372.susgen
FortinetW32/Kryptik.DEQS!tr
AVGWin32:Evo-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan.Loader.DQ?

Trojan.Loader.DQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment