Trojan

Trojan.Agent.BORM removal guide

Malware Removal

The Trojan.Agent.BORM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BORM virus can do?

  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • Authenticode signature is invalid

How to determine Trojan.Agent.BORM?


File Info:

name: 2D3FA7CB594DDAF80760.mlw
path: /opt/CAPEv2/storage/binaries/1c1afab87d2d229b7de1cffeaace1f77dd5964d01eabfdac61aa7407f3a8e18d
crc32: EA482FF5
md5: 2d3fa7cb594ddaf80760415e235e7818
sha1: df0a8d3b82143cfff423e8a9a444a95e3c8a8c31
sha256: 1c1afab87d2d229b7de1cffeaace1f77dd5964d01eabfdac61aa7407f3a8e18d
sha512: b8e938f0d552085b53ccabc26ce63b3ba9ce9092bb110fdd4672458daaf7049f526b8ce82bd9a257c3b2506a4bb083e3e8801a86b2a5bae8fe7c43cd81eedf06
ssdeep: 768:UueztiNkQmblAbtqcG+oFULoeegf+Yd+GYK3z2085wjwzRq8KenEmTfD7avFpw0V:UuC4oblqt/hoFeoeeXY+EDiGwWesFmu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D963D42329C5BD02E2A27F7D02C257F3A357A0B1E5E4AA5376DEAEC5505D206E8C3347
sha3_384: ce6df648142654dc03567505187a049fac2cf61ad6fa3222049f92c339f8d35607f6b37a2d076a073247d6cbe4568c77
ep_bytes: 558bec6aff68c0c040006850bc400064
timestamp: 2005-01-17 02:51:28

Version Info:

CompanyName: Conceptworld Corporation
FileVersion: 0,166,35,33
LegalCopyright: Attack (C) 2014
ProductVersion: 0,170,25,233
ProductName: Adventuring Trade

Trojan.Agent.BORM also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanTrojan.Agent.BORM
FireEyeGeneric.mg.2d3fa7cb594ddaf8
CAT-QuickHealRansome.Crowti.OB4
ALYacTrojan.Agent.BORM
VIPRETrojan.Win32.Generic.pak!cobra
K7AntiVirusTrojan ( 0055e3ef1 )
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.b594dd
BaiduWin32.Trojan.Kryptik.qb
SymantecSMG.Ransom!gen
ESET-NOD32a variant of Win32/Kryptik.EGUP
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.BORM
NANO-AntivirusTrojan.Win32.Dwn.dyzlpx
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
TencentMalware.Win32.Gencirc.10ba0fc9
Ad-AwareTrojan.Agent.BORM
EmsisoftTrojan.Agent.BORM (B)
DrWebTrojan.DownLoader17.64754
ZillyaTrojan.Cryptodef.Win32.2053
TrendMicroRansom_HPCRYPTESLA.SM2
McAfee-GW-EditionArtemis!Trojan
SophosML/PE-A + Mal/Ransom-EG
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Cryptodef.jt
Antiy-AVLTrojan/Generic.ASMalwS.17C9345
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ViRobotTrojan.Win32.CryptoWall.270336.C
GDataTrojan.Agent.BORM
McAfeeArtemis!2D3FA7CB594D
MAXmalware (ai score=86)
VBA32BScope.TrojanDownloader.Talalpek
TrendMicro-HouseCallRansom_HPCRYPTESLA.SM2
RisingTrojan.Generic@ML.92 (RDML:zgEORg9pheRZqex6WnCHWg)
YandexTrojan.GenAsa!US/MIvNoE8Y
FortinetW32/Kryptik.EQBR!tr
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Agent.BORM?

Trojan.Agent.BORM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment