Ransom Trojan

Trojan.Ransom.BOW information

Malware Removal

The Trojan.Ransom.BOW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.BOW virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs

How to determine Trojan.Ransom.BOW?


File Info:

crc32: EF6C131F
md5: ff19b6df5d38d754a7cbfb6acbb5157b
name: FF19B6DF5D38D754A7CBFB6ACBB5157B.mlw
sha1: 4340bdc082b7f8d6b7de06cee09e47409ccfb3d8
sha256: 4ebc124c7e19c2a87f911e9972f365f6fd0ef1532981a828b085e0a6bac2e310
sha512: 37c84779e5673691237983a7372119f55e8522fc1e8b63e810e16d5322e5bcda48c05fa8801455ee38cf15a1ad581fae66958f422fbe32d818e21b3d4d20bd69
ssdeep: 6144:A7kcPazl6C4wwx+jhNwQmmVE0G/BB4JgEtRWPqOOq7L/I2g:A7k8azl6+hNw50MX42Ety/Oq7LI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Ransom.BOW also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.BOW
FireEyeGeneric.mg.ff19b6df5d38d754
McAfeeGenericRXBI-UV!FF19B6DF5D38
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Yakes.tazo
K7AntiVirusTrojan ( 0050bc621 )
BitDefenderTrojan.Ransom.BOW
K7GWTrojan ( 0050bc621 )
Cybereasonmalicious.f5d38d
BitDefenderThetaGen:NN.ZexaF.34590.sq3@aO29z7ij
SymantecRansom.TeslaCrypt
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Yakes-7008632-0
KasperskyTrojan.Win32.Yakes.tazo
AlibabaTrojan:Win32/Yakes.d4fde690
NANO-AntivirusTrojan.Win32.Androm.enuhvh
ViRobotTrojan.Win32.Z.Locky.309602
TencentMalware.Win32.Gencirc.10bbaebb
Ad-AwareTrojan.Ransom.BOW
TACHYONRansom/W32.Locky.309602
EmsisoftTrojan.Ransom.BOW (B)
ComodoMalware@#31r2br5d50h31
F-SecureHeuristic.HEUR/AGEN.1103117
DrWebTrojan.Encoder.3976
ZillyaTrojan.GenericKD.Win32.37688
TrendMicroRansom_LOCKY.AUSVZ
McAfee-GW-EditionGenericRXBI-UV!FF19B6DF5D38
SophosMal/Generic-S
JiangminTrojan.Locky.dip
eGambitUnsafe.AI_Score_99%
AviraHEUR/AGEN.1103117
Antiy-AVLTrojan/Win32.TSGeneric
KingsoftWin32.Troj.Yakes.ta.(kcloud)
MicrosoftRansom:Win32/Locky
SUPERAntiSpywareBackdoor.Andromeda/Variant
ZoneAlarmTrojan.Win32.Yakes.tazo
GDataTrojan.Ransom.BOW
CynetMalicious (score: 90)
AhnLab-V3Trojan/Win32.Locky.C1922152
VBA32OScope.Malware-Cryptor.Hlux
ALYacTrojan.Ransom.LockyCrypt
MAXmalware (ai score=100)
MalwarebytesRansom.Spora
PandaTrj/Genetic.gen
ZonerTrojan.Win32.56525
ESET-NOD32a variant of Win32/Injector.DNZS
TrendMicro-HouseCallRansom_LOCKY.AUSVZ
RisingRansom.Locky!8.1CD4 (CLOUD)
YandexTrojan.GenAsa!wLl2+7f1qA0
SentinelOneStatic AI – Suspicious PE
FortinetW32/Injector.DOLH!tr
WebrootW32.Ransom.Locky
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Botnet.Yakes.HwcB8FwA

How to remove Trojan.Ransom.BOW?

Trojan.Ransom.BOW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment