Malware

What is “Downloader.Win32.DownloaderGuide.pwj”?

Malware Removal

The Downloader.Win32.DownloaderGuide.pwj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.DownloaderGuide.pwj virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Downloader.Win32.DownloaderGuide.pwj?


File Info:

name: AE18C399EF8208AAF1D1.mlw
path: /opt/CAPEv2/storage/binaries/eb9bee76193d592bdbf9936bcc1a4b6b0cd68d15fc10b887ef550156659fb6ff
crc32: A86FFCA7
md5: ae18c399ef8208aaf1d157f79cb1150d
sha1: 1020d4cbe0cd39efa82db69d0c76996a4eeba704
sha256: eb9bee76193d592bdbf9936bcc1a4b6b0cd68d15fc10b887ef550156659fb6ff
sha512: 19b8af80acd63e10de267c0d32de22633be649e5a51f420d16af29b9f8ef4d12e2e29e1a31a37ae32deb660a67f1c8b2c94e3b30a755b74400d2c7a308b3980f
ssdeep: 6144:7OcH7FWm10gny1LOSCzs7FsDjW7sjKQK1MF+jO40SqDBxLQaXhFZMzFozkE/:ycbFW7MaCzXDjDKaFuiSaWQhFZMzFoz/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E97412E5B61950B7E5624AF064E297C74835AE6A53C0708A83F433215B796B8FF3C32D
sha3_384: f7ea7cf201860f5c8b99cbf510f0e8d970431abf65c5b056875506d06387c9557759089fe798c64d7a31243403adc412
ep_bytes: 60be00c043008dbe0050fcff5783cdff
timestamp: 2016-09-28 10:01:41

Version Info:

FileVersion: 3.1.0.201

Downloader.Win32.DownloaderGuide.pwj also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
CAT-QuickHealPUA.Freemiumgm2.Gen
SkyhighBehavesLike.Win32.Sytro.fc
McAfeeGenericRXQJ-XR!397D76D89B79
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
SymantecSMG.Heur!gen
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/DownloadGuide.D potentially unwanted
APEXMalicious
Kasperskynot-a-virus:Downloader.Win32.DownloaderGuide.pwj
NANO-AntivirusTrojan.Win32.Dwn.egxamc
F-SecureAdware.ADWARE/Adware.Gen3
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.ae18c399ef8208aa
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
JiangminDownloader.DownloaderGuide.va
AviraADWARE/Adware.Gen3
Antiy-AVLGrayWare[AdWare]/Win32.DownloadGuide.d
MicrosoftPUADlManager:Win32/DownloadGuide
XcitiumApplication.Win32.DownloadGuide.TN@76upxe
ZoneAlarmnot-a-virus:Downloader.Win32.DownloaderGuide.pwj
GDataWin32.Trojan.PSE.1LY2XF0
CynetMalicious (score: 100)
AhnLab-V3Adware/Win.Generic.R638761
VBA32BScope.Downloader.DownloaderGuide
Cylanceunsafe
RisingAdware.DownloadGuide!1.F33C (CLASSIC)
YandexPUA.Downloader!bdq4wh2xsu0
IkarusPUA.DownloadGuide
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaF.36802.vmLfa8pWEoj
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Downloader.Win32.DownloaderGuide.pwj?

Downloader.Win32.DownloaderGuide.pwj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment