Trojan

About “Trojan-Dropper.Win32.Daws.bkxy” infection

Malware Removal

The Trojan-Dropper.Win32.Daws.bkxy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Daws.bkxy virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempted to write directly to a physical drive
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Collects information to fingerprint the system
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan-Dropper.Win32.Daws.bkxy?


File Info:

name: CBEDAAA2D52150E13C19.mlw
path: /opt/CAPEv2/storage/binaries/5cae9b95dcce9573b0cdf9d4e9a6d2e21e4883ce6eff74a67d5151b5961bc219
crc32: 95F0D8CB
md5: cbedaaa2d52150e13c190c9edf60a8b6
sha1: 0b62f996aa2f5624cfa6ea69e4a04d1a0c1b1ba3
sha256: 5cae9b95dcce9573b0cdf9d4e9a6d2e21e4883ce6eff74a67d5151b5961bc219
sha512: 11a075e07d878288b6e0f73f9dc3a312b68efcfe5338b0aa351650251abf5f400598edd8142e836a74c636fdfc217014316cd8e52a5c3e63b6cccc59240835d9
ssdeep: 24576:M/oO1EqrN22X1e213WWAKkYWmoIQw7ymxiOo5hmRE+RU5:uRB2o1e2Q8WPpAymxiOo5hmRpRU5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1292523857D14D151D858D732D2B5A77B0E20BCA0ED61860FF084FA6DB7B53837A2E872
sha3_384: ebeeb66d45c652601a97208558c7908cbded3977fe9f117990fc48eb458d4c3914e09c4dc502d50459f5ee06c33ea867
ep_bytes: 558bec83ec4456ff15a44040008bf08a
timestamp: 2010-02-04 10:22:17

Version Info:

CompanyName: LogMeIn, Inc.
FileDescription: LogMeIn Rescue
FileVersion: 6.2.370
InternalName: Rescue
LegalCopyright: Copyright © 2005-2010 LogMeIn, Inc. US patents pending.
OriginalFilename: LMIRescue.exe
ProductName: LogMeIn Rescue
ProductVersion: 6.2.370
Translation: 0x0409 0x04b0

Trojan-Dropper.Win32.Daws.bkxy also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Daws.totq
SkyhighArtemis
McAfeeArtemis!CBEDAAA2D521
Cylanceunsafe
CynetMalicious (score: 100)
KasperskyTrojan-Dropper.Win32.Daws.bkxy
NANO-AntivirusTrojan.Win32.Daws.bbxgoa
TencentWin32.Trojan-Dropper.Daws.Hajl
DrWebTrojan.DownLoader8.16971
JiangminTrojanDropper.Daws.ceg
Antiy-AVLTrojan/Win32.Possiblethreat
Kingsoftmalware.kb.a.987
XcitiumTrojWare.Win32.TrojanDropper.Daws.AWVZ@7pjjd8
ZoneAlarmTrojan-Dropper.Win32.Daws.bkxy
VBA32TrojanDropper.Daws
RisingTrojan.Generic@AI.100 (RDML:WA6RcCi4W+jPhICijFBqzg)
YandexTrojan.GenAsa!hx7DPWkISB4
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Daws.BKXY!tr
Cybereasonmalicious.6aa2f5
DeepInstinctMALICIOUS

How to remove Trojan-Dropper.Win32.Daws.bkxy?

Trojan-Dropper.Win32.Daws.bkxy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment