Malware

How to remove “Win32:Dropper-JQQ [Drp]”?

Malware Removal

The Win32:Dropper-JQQ [Drp] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Dropper-JQQ [Drp] virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics

Related domains:

www.wk1888.com
www.af0575.com
www.fz0575.com

How to determine Win32:Dropper-JQQ [Drp]?


File Info:

crc32: 88DAA8FC
md5: b94514d2c96e89e30ac9a1162e0cf33c
name: B94514D2C96E89E30AC9A1162E0CF33C.mlw
sha1: f207b38d8106a82518627946fff3e26e76671b96
sha256: 4a4df4b7b6fa96a888247a84d004604f88fd3cb7c2c2ce55caaa43a419e75f03
sha512: f8e621e6ecd8c0f2339b06607718432a89204b823428ab7fbf98d7b400a6e895bb42a45ea146eca38c22449239c12e2bf631bbebd5bbd77b598e7f6d9bc6cb05
ssdeep: 24576:25Oh8v5wcO4l5axzhl4GKz0iPz3McGJJYtvjo:C2q5Ljl5advoY6z8OtvE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32:Dropper-JQQ [Drp] also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 003564d61 )
Elasticmalicious (high confidence)
DrWebTrojan.SpyBot.592
CynetMalicious (score: 99)
CAT-QuickHealBackdoor.Zegost.B
ALYacDropped:Trojan.GenericKD.31060208
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojanDropper:Win32/Dorv.15616591
K7GWTrojan ( 003564d61 )
Cybereasonmalicious.2c96e8
BaiduWin32.Trojan.Dialer.d
CyrenW32/Zegost.MYEI-4034
SymantecBackdoor.Trojan
ESET-NOD32multiple detections
ZonerTrojan.Win32.22067
APEXMalicious
AvastWin32:Dropper-JQQ [Drp]
ClamAVWin.Malware.Generickdz-6957625-0
KasperskyHEUR:Trojan.Win32.Farfli.gen
BitDefenderDropped:Trojan.GenericKD.31060208
NANO-AntivirusTrojan.Win32.Scar.bcbyug
MicroWorld-eScanDropped:Trojan.GenericKD.31060208
Ad-AwareDropped:Trojan.GenericKD.31060208
SophosML/PE-A + Troj/Scar-BZ
ComodoWorm.Win32.Dropper.RA@1qraug
BitDefenderThetaAI:Packer.EEAC388A20
TrendMicroBKDR_ZEGOST.AD
McAfee-GW-EditionExploit-MS03-043.a
FireEyeDropped:Trojan.GenericKD.31060208
EmsisoftDropped:Trojan.GenericKD.31060208 (B)
JiangminTrojan.Generic.cakkw
AviraHEUR/AGEN.1111177
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASBOL.B06
MicrosoftTrojan:Win32/Dorv.A
ZoneAlarmHEUR:Trojan.Win32.Farfli.gen
GDataWin32.Trojan.PSE.19Q2126
McAfeeArtemis!B94514D2C96E
MAXmalware (ai score=81)
VBA32SScope.Trojan.SvcHorse.01643
MalwarebytesBackdoor.Farfli
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_ZEGOST.AD
RisingTrojan.Injector!1.A1C3 (CLASSIC)
YandexTrojan.GenAsa!pd90PKR7MRk
IkarusTrojan.Win32.Dialer
FortinetW32/Farfli.PZ!tr
AVGWin32:Dropper-JQQ [Drp]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Dorv.HyoDXBIB

How to remove Win32:Dropper-JQQ [Drp]?

Win32:Dropper-JQQ [Drp] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment