Trojan

TrojanDownloader.Small.BPQ4 (file analysis)

Malware Removal

The TrojanDownloader.Small.BPQ4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader.Small.BPQ4 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine TrojanDownloader.Small.BPQ4?


File Info:

name: ED6907193F8B9CEC458B.mlw
path: /opt/CAPEv2/storage/binaries/2b64a130cf2170696faf539e3761f48234fd2360e99512c0ed3a784996905560
crc32: F0CE7EA8
md5: ed6907193f8b9cec458b6e009d9c1ced
sha1: 373b8365746234dfa02e931015c6da89cbe2cbff
sha256: 2b64a130cf2170696faf539e3761f48234fd2360e99512c0ed3a784996905560
sha512: 7844ec12bd3496c8fcac8e681e4d354ef4e9dae2701cdc7b80497926211c604bb709b50e4a3c5b0a67e427f8e326b6f541b19a613c13552001445d2d56eb0bc3
ssdeep: 12288:uLXmgMb4Xd+Uh8ggdE8Ox4GoyPV4qOr1nBMIQn6LuH:uDmgMbVujg9u4GBPVLOr1nvM6LG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E0D4AE12F391CC32D0D741B9596AC7306EBE9A30173B5853B7E559893E302E2AB3935B
sha3_384: 517176bb1791884d00a9b7e5ca9d3262273c78211f94da5922726332e15d5bb23132d0364e9092b6f5bb4a89b519e48f
ep_bytes: 6a6068b8744600e8e91e0000bf940000
timestamp: 2007-04-29 11:43:12

Version Info:

CompanyName: Simon Tatham
ProductName: PuTTY suite
FileDescription: SSH, Telnet and Rlogin client
InternalName: PuTTY
OriginalFilename: PuTTY
FileVersion: Release 0.60
ProductVersion: Release 0.60
LegalCopyright: Copyright © 1997-2007 Simon Tatham.
Translation: 0x0809 0x04b0

TrojanDownloader.Small.BPQ4 also known as:

AVGWin32:Geral [Trj]
FireEyeGeneric.mg.ed6907193f8b9cec
CAT-QuickHealTrojanDownloader.Small.BPQ4
CylanceUnsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005057171 )
K7GWTrojan ( 005057171 )
BaiduWin32.Backdoor.Agent.n
VirITWin32.Virut.CI
CyrenW32/S-d32c59ba!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AntiAV.NFM
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Trojan.KillAV-47
NANO-AntivirusTrojan.Win32.Scar.cshit
AvastWin32:Geral [Trj]
DrWebTrojan.BrowseBan.565
McAfee-GW-EditionDownloader-FUV!ED6907193F8B
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Downloader.Agent.AD
JiangminHeur:TrojanDownloader.Agent
AviraWORM/Citeary.doua
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
Acronissuspicious
McAfeeDownloader-FUV!ED6907193F8B
VBA32Trojan.Agent2
MalwarebytesMalware.AI.2987880255
RisingVirus.Begseabug!1.D877 (CLASSIC)
IkarusTrojan.Win32.Swisyn
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/AntiAV.NFM!tr
Cybereasonmalicious.93f8b9

How to remove TrojanDownloader.Small.BPQ4?

TrojanDownloader.Small.BPQ4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment