Malware

Should I remove “Win64/BazarLoader.R”?

Malware Removal

The Win64/BazarLoader.R is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/BazarLoader.R virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Win64/BazarLoader.R?


File Info:

crc32: 9A6D7482
md5: fa9ecf2629219fb0629f3f0c0e1bf587
name: upload_file
sha1: 561e4c8c3de26ca6954f9f1ae4fa0b51d6d328b2
sha256: bc0f09c3efc74215e93165fdda0d37b6f19566a25f04b1ef89713de41524a1e0
sha512: 72ff41a60a8aa0c4cac9b73d7f1e1dfee211f8c4912a8358888b118e948c38e2e219934aeb4db272ff8679b053de38aa4504cbbdc6df795abc6915feb0e44521
ssdeep: 196608:akYZ6ZRSJJ01qMlgkfBe0sx7BogxN44qYO2FLOyomFHKnPAWFLOyomFHKnPB:ahJcBzE4BYHFeFI
type: PE32+ executable (GUI) x86-64, for MS Windows

Version Info:

LegalCopyright: TODO: (C) x3002x4fddx7559x6240x6709x6743x5229x3002
InternalName: cow2.exe
FileVersion: 1.0.0.1
CompanyName: TODO:
ProductName: TODO:
ProductVersion: 1.0.0.1
FileDescription: cow2
OriginalFilename: cow2.exe
Translation: 0x0804 0x04b0

Win64/BazarLoader.R also known as:

MicroWorld-eScanTrojan.Agent.EXVW
FireEyeTrojan.Agent.EXVW
CAT-QuickHealTrojandownloader.Bazloader
McAfeeArtemis!FA9ECF262921
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Bazloader.a!c
K7AntiVirusTrojan ( 005718d91 )
BitDefenderTrojan.Agent.EXVW
K7GWTrojan ( 005718d91 )
CrowdStrikewin/malicious_confidence_100% (W)
InvinceaMal/Generic-S
SymantecTrojan.Gen.2
KasperskyTrojan-Downloader.Win32.Bazloader.g
AlibabaTrojanDownloader:Win32/Bazloader.f47ea20f
RisingTrojan.Bazar!8.121E3 (TFE:5:zotW1BtlPpF)
Ad-AwareTrojan.Agent.EXVW
EmsisoftMalCert-S.CX (A)
Comodofls.noname@0
F-SecureTrojan.TR/Agent.ulnqd
DrWebTrojan.Packed2.42633
TrendMicroTrojan.Win64.BAZALOADER.B
McAfee-GW-EditionArtemis!Trojan
WebrootW32.Trojan.Bazarloader
AviraTR/Agent.ulnqd
MicrosoftTrojan:Win64/CryptInject.KSH!cert
ArcabitTrojan.Agent.EXVW
ZoneAlarmTrojan-Downloader.Win32.Bazloader.g
GDataTrojan.Agent.EXVW
AhnLab-V3Trojan/Win64.BazarLoader.R353552
ALYacTrojan.Agent.Bazar
MAXmalware (ai score=82)
MalwarebytesTrojan.Bazar
PandaTrj/CI.A
ESET-NOD32Win64/BazarLoader.R
TrendMicro-HouseCallTrojan.Win64.BAZALOADER.B
IkarusTrojan.Win64.Bazarloader
FortinetW64/BazarLoader.R!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Downloader.b22

How to remove Win64/BazarLoader.R?

Win64/BazarLoader.R removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Malware

Win64/BazarLoader.R information

Malware Removal

The Win64/BazarLoader.R is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/BazarLoader.R virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Win64/BazarLoader.R?


File Info:

crc32: 1592C5C4
md5: 8c32e44ea7eadbeca921d8e292171556
name: upload_file
sha1: 7bbd86dd91e2a43ae6d7a132ac1918875146a40c
sha256: f471cbd53a52d27053c33c4fd18fe2305f94f947d8cc2275c3506fe74c2f11f5
sha512: 5ab2311c7eb9b2b73450cd3a16d16261990c9c14723fc990daf548a45b3c135761613b4b9f612c93083d8f7fcecc46ba8665e197eaebdc914426d38d074ba0f2
ssdeep: 196608:akYZ6ZRSJJ01qMlXkfBe0sx7BogxN44qYO2FLOyomFHKnPAWFLOyomFHKnPr:ahJNBzE4BYHFeFG
type: PE32+ executable (GUI) x86-64, for MS Windows

Version Info:

LegalCopyright: TODO: (C) x3002x4fddx7559x6240x6709x6743x5229x3002
InternalName: cow2.exe
FileVersion: 1.0.0.1
CompanyName: TODO:
ProductName: TODO:
ProductVersion: 1.0.0.1
FileDescription: cow2
OriginalFilename: cow2.exe
Translation: 0x0804 0x04b0

Win64/BazarLoader.R also known as:

MicroWorld-eScanTrojan.Agent.EXVW
FireEyeTrojan.Agent.EXVW
CAT-QuickHealTrojandownloader.Bazloader
ALYacTrojan.Agent.Bazar
CylanceUnsafe
K7AntiVirusTrojan ( 005718d91 )
BitDefenderTrojan.Agent.EXVW
K7GWTrojan ( 005718d91 )
InvinceaMal/Generic-S
SymantecTrojan.Gen.2
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Bazloader.c
AlibabaTrojanDownloader:Win64/Bazloader.407cd51c
AegisLabTrojan.Win32.Bazloader.a!c
RisingTrojan.Bazar!8.121E3 (TFE:5:zotW1BtlPpF)
Ad-AwareTrojan.Agent.EXVW
Comodofls.noname@0
F-SecureTrojan.TR/Agent.ulnqd
DrWebTrojan.Packed2.42633
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win64.BAZALOADER.B
McAfee-GW-EditionArtemis!Trojan
EmsisoftMalCert-S.CX (A)
AviraTR/Agent.ulnqd
MAXmalware (ai score=80)
MicrosoftTrojan:Win64/CryptInject.KSH!cert
ZoneAlarmTrojan-Downloader.Win32.Bazloader.c
GDataTrojan.Agent.EXVW
AhnLab-V3Trojan/Win64.BazarLoader.R353552
MalwarebytesTrojan.Bazar
PandaTrj/CI.A
ESET-NOD32Win64/BazarLoader.R
IkarusTrojan.Win64.Bazarloader
FortinetW32/Bazloader.C!tr.dldr
AVGFileRepMalware

How to remove Win64/BazarLoader.R?

Win64/BazarLoader.R removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment