Malware

Win32:Dropper-NQN [Trj] removal tips

Malware Removal

The Win32:Dropper-NQN [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Dropper-NQN [Trj] virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32:Dropper-NQN [Trj]?


File Info:

name: 9A12810AF4FB9F7B38D3.mlw
path: /opt/CAPEv2/storage/binaries/a6817d542340f8f2ad8d158c8f46f472696e7bd89f9937fd1bbe1cadf50597a0
crc32: 4435A040
md5: 9a12810af4fb9f7b38d3f7585e6b14ef
sha1: 223b0f43a80c223e984d130b490ad5c7f55d99bb
sha256: a6817d542340f8f2ad8d158c8f46f472696e7bd89f9937fd1bbe1cadf50597a0
sha512: 9d048c9ba98ec773278cddb0e834570f349eee736787a8cf68def69ea85fee03763176ff1dbbbd99d64ddec7954cf6b4ce30fb98872c21ea8cd1b4f4c6dcb873
ssdeep: 12288:lb4bBxdi79LrlBDCfdrKXBkXfcJUMLhRpCt+A4:lb4b7dkLrlB0d8aC/hjCtI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EFA4E0203581C037D1A716344AE5C779A5BE79A10B21E4C73BE8EBBE6E702E1DA35347
sha3_384: bc72266e5201adb71e57de4855d3d1ef61d89d04fec5b23701539405cd7390629a4742ac83742406010f3838af66f5cd
ep_bytes: e8635f0000e989feffff8bff558bec5d
timestamp: 2009-10-01 09:07:11

Version Info:

ProductName: WinRAR
CompanyName: Alexander Roshal
FileDescription: WinRAR archiver
FileVersion: 4.1.0
ProductVersion: 4.1.0
InternalName: WinRAR
LegalCopyright: Copyright © Alexander Roshal 1993-2011
OriginalFilename: WinRAR.exe
Translation: 0x0000 0x0000

Win32:Dropper-NQN [Trj] also known as:

BkavW32.AIDetectMalware
AVGWin32:Dropper-NQN [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.94651
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.gc
McAfeeGenericRXMG-EE!9A12810AF4FB
MalwarebytesWapomi.Virus.FileInfector.DDS
ZillyaTrojan.Agent.Win32.3896022
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0043c2cb1 )
K7GWTrojan ( 0043c2cb1 )
Cybereasonmalicious.af4fb9
BitDefenderThetaGen:NN.ZexaF.36802.Cy0@au18qHji
SymantecSMG.Heur!gen
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDropper.Agent.QGO
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Cuegoe-6336261-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.94651
NANO-AntivirusTrojan.Win32.Agent.csbmbm
AvastWin32:Dropper-NQN [Trj]
TencentTrojan.Win32.Agent.xe
EmsisoftTrojan.GenericKDZ.94651 (B)
BaiduWin32.Trojan-Dropper.Agent.ab
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebTrojan.Siggen5.38304
VIPRETrojan.GenericKDZ.94651
TrendMicroTROJ_ORBUS.SMA
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.9a12810af4fb9f7b
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.biajg
AviraTR/Crypt.XPACK.Gen7
MAXmalware (ai score=84)
Antiy-AVLTrojan[Backdoor]/Win32.Salgorea.gen
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDropper:Win32/Salgorea.AI!MTB
XcitiumApplication.Win32.Amonetize.NE@5te978
ArcabitTrojan.Generic.D171BB
ZoneAlarmVHO:Trojan-Dropper.Win32.Convagent.gen
GDataWin32.Trojan.PSE.168GMQ4
GoogleDetected
AhnLab-V3Trojan/Win.Orbus.R638935
Acronissuspicious
VBA32BScope.TrojanDropper.Cuegoe
ALYacTrojan.GenericKDZ.94651
Cylanceunsafe
PandaGeneric Suspicious
TrendMicro-HouseCallTROJ_ORBUS.SMA
RisingBackdoor.[OceanLotus]Salgorea!1.C3DC (CLASSIC)
YandexTrojan.GenAsa!fgR3yXzCbR8
IkarusTrojan-Dropper.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Upatre.0285!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan[downloader]:Win/Cuegoe.76ff9a1c

How to remove Win32:Dropper-NQN [Trj]?

Win32:Dropper-NQN [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment