Trojan

Win32/TrojanDownloader.Tiny.NKQ malicious file

Malware Removal

The Win32/TrojanDownloader.Tiny.NKQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Tiny.NKQ virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/TrojanDownloader.Tiny.NKQ?


File Info:

name: 43D3F8FBEBB6A8AAB9A9.mlw
path: /opt/CAPEv2/storage/binaries/77900629a85c0f2ec14294910337bbd0a22f11b503dbaf11e2f1106ec227ef45
crc32: 08AECD03
md5: 43d3f8fbebb6a8aab9a937a3dc39daa2
sha1: c8b977ecdf9025dde751b5bb9925813d6ef30808
sha256: 77900629a85c0f2ec14294910337bbd0a22f11b503dbaf11e2f1106ec227ef45
sha512: 49fb0d5e2ecadf96ed52c8aacbc51cb57a1baf5cf731dd373f5b2ba0416c32a7e84af594027815b773c022f4534f86e4a89cce568c8a671cecc3688ee8890503
ssdeep: 384:Tmvf/mQejKQ0A4rXu3ujXmvUB1Ym5ddd0svdCAVJBknt7fgbFJ+Wyd/9E:IznhXu3ujW8/cWclE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T117B2D4169BE21839E6A7157CDCBA86D140AC7E254FD190CFAA4E36CD04323D572F1A8B
sha3_384: ab7432098ee701c5db637917411e5b1c39cc1956453bdc1800db231ef46df80e8817cb1200d0944286ba013bfd1bf87f
ep_bytes: 558bec6aff681041600068a033600064
timestamp: 2011-06-24 03:55:03

Version Info:

0: [No Data]

Win32/TrojanDownloader.Tiny.NKQ also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.1764680
FireEyeGeneric.mg.43d3f8fbebb6a8aa
CAT-QuickHealTrojanDownloader.Upatre.AA4
ALYacTrojan.GenericKD.1764680
MalwarebytesTrojan.Downloader
ZillyaTrojan.Bublik.Win32.14183
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan-Downloader ( 0049d1851 )
K7GWTrojan-Downloader ( 0049d1851 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36164.bqX@a4hFlsdc
VirITTrojan.Win32.Visucius.BG
CyrenW32/Trojan.XIPO-1831
ESET-NOD32Win32/TrojanDownloader.Tiny.NKQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Bublik.crbu
BitDefenderTrojan.GenericKD.1764680
NANO-AntivirusTrojan.Win32.Bublik.dciuex
AvastWin32:Agent-AUID [Trj]
TencentMalware.Win32.Gencirc.114aca47
SophosMal/Zbot-QL
BaiduWin32.Trojan-Downloader.Waski.a
F-SecureTrojan-Downloader:W32/Upatre.I
DrWebTrojan.DownLoad3.33795
VIPRETrojan.GenericKD.1764680
TrendMicroTROJ_UPATRE.SM01
McAfee-GW-EditionBehavesLike.Win32.Downloader.mm
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.1764680 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.1764680
JiangminTrojan/Bublik.gzm
AviraTR/Crypt.ZPACK.Gen2
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.Bublik
XcitiumBackdoor.Win32.Androm.EQ@5e59a9
ArcabitTrojan.Generic.D1AED48
ZoneAlarmTrojan.Win32.Bublik.crbu
MicrosoftTrojan:Win32/Upatre.MA!MTB
GoogleDetected
AhnLab-V3Downloader/Win32.Upatre.R113371
McAfeeDownloader-FSH
VBA32BScope.Trojan.Bublik
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.26088
TrendMicro-HouseCallTROJ_UPATRE.SM01
RisingDownloader.Upatre!8.B5 (TFE:5:7q01TsPD0uN)
YandexTrojan.Bublik!rUGOE2KFbvM
IkarusTrojan.Win32.Bublik
FortinetW32/Waski.A!tr
AVGWin32:Agent-AUID [Trj]
DeepInstinctMALICIOUS

How to remove Win32/TrojanDownloader.Tiny.NKQ?

Win32/TrojanDownloader.Tiny.NKQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment