Malware

How to remove “Win32:Downloader-OPN [Trj]”?

Malware Removal

The Win32:Downloader-OPN [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Downloader-OPN [Trj] virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32:Downloader-OPN [Trj]?


File Info:

name: 4790BA576C7EB3CDB666.mlw
path: /opt/CAPEv2/storage/binaries/2e0ebacc000745651f972b29ce4bfd001f9854ac660b2098252119b4e732cda3
crc32: 42E8FFA9
md5: 4790ba576c7eb3cdb66667ee84c39504
sha1: fcbcd79a58efff336d78bb7f614fa229c7fd922f
sha256: 2e0ebacc000745651f972b29ce4bfd001f9854ac660b2098252119b4e732cda3
sha512: 35d5c96e57b89e45474be65c0d3c2889ac5ba83ec0fa0f55ff992a63876fb7d6dad26980ea703fab6b9b559b8eda6c371d95862cbbbe4203968c8549861e7bb0
ssdeep: 6144:zpoxOK9DFeh2c/Yatw31Fz0p2dyxwxMMr1xsAgqiRlKTG55GTfnYa/tTKiWCDGuB:jPTaPTxUmO4mi8fmVDNth7awy8MGJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10CC40935E6247A2BF422A0F5629E9AA64018AD30331457C7FBC54F9970F50E2973BF1B
sha3_384: 58f5532424ab61252c312ed1cb7b5d3aba5ffd3adbd81dc48abb5ca7351915b0fc738665c70ff1012a7212506ac3b0ef
ep_bytes: e892040000e936fdffff8bff558bec81
timestamp: 2012-05-18 19:08:13

Version Info:

Comments:
CompanyName: Microsoft Corporation
FileDescription: Performance Log Utility
FileVersion: 6.1.7600.16385
InternalName: Logman.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
LegalTrademarks: © Microsoft Corporation. All rights reserved.
OriginalFilename: Logman.exe.mui
PrivateBuild: Logman.exe.mui
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7600.16385
SpecialBuild: 6.1.7600.16385
Translation: 0x0409 0x04b0

Win32:Downloader-OPN [Trj] also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.lCcB
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
SkyhighBehavesLike.Win32.Mutopy.hh
McAfeeMutopy-BAB!4790BA576C7E
MalwarebytesRodecap.Trojan.Downloader.DDS
ZillyaTrojan.Generic.Win32.255129
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0053c3c71 )
AlibabaMalware:Win32/km_2c6b8.None
K7GWTrojan ( 0053c3c71 )
CrowdStrikewin/malicious_confidence_90% (W)
ArcabitTrojan.Generic.D2CB0E4D
SymantecTrojan.Gen.MBT
ClamAVWin.Trojan.Multi-6413508-0
BitDefenderTrojan.GenericKD.46861901
MicroWorld-eScanTrojan.GenericKD.46861901
AvastWin32:Downloader-OPN [Trj]
TencentMalware.Win32.Gencirc.13b1a772
EmsisoftTrojan.GenericKD.46861901 (B)
F-SecureTrojan.TR/Kazy.34213.jh
DrWebTrojan.DownLoader6.10883
VIPRETrojan.GenericKD.46861901
TrendMicroTROJ_MUTOPY.SMYN
FireEyeTrojan.GenericKD.46861901
SophosTroj/Dapato-A
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/Kazy.34213.jh
Antiy-AVLTrojan/Win32.AGeneric
XcitiumTrojWare.Win32.Downloader.Jorik.AO@4mxqf9
MicrosoftTrojan:Win32/Mutopy.A
GDataTrojan.GenericKD.46861901
VaristW32/Troj_Obfusc.AI.gen!Eldorado
AhnLab-V3Trojan/Win32.HDC.C53646
ALYacTrojan.GenericKD.46861901
MAXmalware (ai score=86)
Cylanceunsafe
TrendMicro-HouseCallTROJ_MUTOPY.SMYN
RisingTrojan.Mutopy!1.9D89 (CLASSIC)
IkarusTrojan.Win32.Jorik
FortinetW32/Dapato.A!tr
AVGWin32:Downloader-OPN [Trj]
DeepInstinctMALICIOUS

How to remove Win32:Downloader-OPN [Trj]?

Win32:Downloader-OPN [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment