Trojan

Trojan.Downloader.bOWbaWzGcmn information

Malware Removal

The Trojan.Downloader.bOWbaWzGcmn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Downloader.bOWbaWzGcmn virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Trojan.Downloader.bOWbaWzGcmn?


File Info:

name: 85EE03BC5FD9E168C089.mlw
path: /opt/CAPEv2/storage/binaries/d9f19614bf348e3bbfe22500804ed9da1de90c10bccebd57a8e73f1672b68f5e
crc32: 7F975884
md5: 85ee03bc5fd9e168c0895def024ad656
sha1: cd2da51bb44d0b9ef781839808170a8a6d7448ff
sha256: d9f19614bf348e3bbfe22500804ed9da1de90c10bccebd57a8e73f1672b68f5e
sha512: 9e1c83f8da9159ef237399ac122946f397abbeac3502174b65077c8de3ee036930cf52f8735a707f30444fe368c35501c46236aa2beebdc3bf3ad167ded0937d
ssdeep: 384:TPS5Oi4R7x5SmX6bHUKVyl5qTAjU4dfhDlQiNom9JzPKDlGjZZdgh4ZAx4r6+S9+:j441Mw2qdfFboePKDg/M/xvdeV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D8C2DFA2FD8ECEF9C8C2A4311057A654CBBCCC9A4729930787F64A0E7C5A424DDB05B8
sha3_384: b1832bf9647f257fc16203dedc1e222269b64ae872f2875992cca36af4afe3f8f37c9db05fd44e93bd494e2507c8f5a9
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan.Downloader.bOWbaWzGcmn also known as:

MicroWorld-eScanGen:Trojan.Downloader.bOWbaWzGcmn
FireEyeGeneric.mg.85ee03bc5fd9e168
McAfeeArtemis!85EE03BC5FD9
CylanceUnsafe
ZillyaDownloader.bOWbaWzGcmn.Win32.1
K7AntiVirusTrojan ( 0040f8b51 )
AlibabaTrojanDownloader:Win32/Genome.b325162c
K7GWTrojan ( 0040f8b51 )
Cybereasonmalicious.c5fd9e
CyrenW32/Heuristic-190!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Genome.dtp
BitDefenderGen:Trojan.Downloader.bOWbaWzGcmn
NANO-AntivirusTrojan.Win32.TrjGen.bycbtn
AvastWin32:Trojan-gen
Ad-AwareGen:Trojan.Downloader.bOWbaWzGcmn
SophosMal/Delf-M
ComodoTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
DrWebTrojan.DownLoader9.27236
VIPREGen:Trojan.Downloader.bOWbaWzGcmn
TrendMicroPossible_Virus
McAfee-GW-EditionBehavesLike.Win32.Ipamor.mc
EmsisoftGen:Trojan.Downloader.bOWbaWzGcmn (B)
GDataGen:Trojan.Downloader.bOWbaWzGcmn
JiangminTrojan.Generic.dmupr
AviraTR/Dldr.Delphi.Gen
Antiy-AVLTrojan/Generic.ASMalwS.EF
ArcabitTrojan.Downloader.bOWbaWzGcmn
ZoneAlarmTrojan-Downloader.Win32.Genome.dtp
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
BitDefenderThetaGen:NN.ZelphiF.34754.bOWbaWzGcmn
ALYacGen:Trojan.Downloader.bOWbaWzGcmn
MAXmalware (ai score=100)
VBA32suspected of Trojan.Downloader.gen
MalwarebytesMalware.Heuristic.1004
TrendMicro-HouseCallPossible_Virus
RisingMalware.Undefined!8.C (TFE:5:oXSbCMrApUC)
YandexTrojan.GenAsa!m98lKPqZmP4
IkarusTrojan-Downloader.Win32.Banload
MaxSecureTrojan.Malware.1746636.susgen
FortinetW32/Downloader.C!tr
AVGWin32:Trojan-gen
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan.Downloader.bOWbaWzGcmn?

Trojan.Downloader.bOWbaWzGcmn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment