Spy

Application.PowerSpy.BM removal tips

Malware Removal

The Application.PowerSpy.BM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.PowerSpy.BM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Authenticode signature is invalid

How to determine Application.PowerSpy.BM?


File Info:

name: ACBF2DDA8026AE53D568.mlw
path: /opt/CAPEv2/storage/binaries/054f4774b954cb5532ed6f86deabfcbde395a0812268d1050ede185d5b5152c8
crc32: C7183EDC
md5: acbf2dda8026ae53d568e80101111182
sha1: 975cdd87695a38388bf1423ffdc98611280e9ae1
sha256: 054f4774b954cb5532ed6f86deabfcbde395a0812268d1050ede185d5b5152c8
sha512: d311acf0d1071653f7cea7532fbaeef77fead532a85dcd782bc2ec3cc5ef6b97c5b8f8e00a83413b323ebd3d40287d241a2438a138c5f2ca9f692794c2c78ae6
ssdeep: 192:/TgI1WvQtyEoDYRl+ojde+94lhDjcVPYCD30sUg:/TgI1WvREoSljde+ElgVPfD30sUg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13BD27223BF1FD821E95A47701531069105A67E742A13CF2EBB497A1CCE726C35AF0B1B
sha3_384: a2840ba53d4dfbf8ba6b4bcb4b598b554628754e6bf4c05380cb0664545ea15217225e7b124220da885ba8770a10d2f0
ep_bytes: 6828204000e8eeffffff000000000000
timestamp: 2009-11-03 13:14:58

Version Info:

Translation: 0x0409 0x04b0
CompanyName: EMX
ProductName: svchost
FileVersion: 2.20
ProductVersion: 2.20
InternalName: symserv
OriginalFilename: symserv.exe

Application.PowerSpy.BM also known as:

BkavW32.Common.54622273
LionicRiskware.Win32.PowerSpy.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.PowerSpy.BM
FireEyeApplication.PowerSpy.BM
SkyhighSpyware-PowerSpy.a
McAfeeSpyware-PowerSpy.a
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.VB.Win32.173416
SangforSpyware.Win32.Powerspy.Vp4g
K7AntiVirusHacktool ( 005287401 )
AlibabaTrojanSpy:Win32/PowerSpy.83500e4d
K7GWHacktool ( 005287401 )
Cybereasonmalicious.a8026a
SymantecSpyware.PowerSpy
ESET-NOD32a variant of Win32/Spy.VB.NFZ
APEXMalicious
TrendMicro-HouseCallSPYW_POWERSPY
Kasperskynot-a-virus:Monitor.Win32.PowerSpy.fee
BitDefenderApplication.PowerSpy.BM
NANO-AntivirusRiskware.Win32.PowerSpy.uwatn
AvastWin32:MalwareX-gen [Trj]
TencentMalware.Win32.Gencirc.13ff9f5f
EmsisoftApplication.PowerSpy.BM (B)
F-SecureProgram.APPL/MonitorTool.Gen2
DrWebProgram.PCSpy.157
VIPREApplication.PowerSpy.BM
TrendMicroSPYW_POWERSPY
SophosGeneric Reputation PUA (PUA)
MAXmalware (ai score=99)
JiangminMonitor.PowerSpy.dx
GoogleDetected
AviraAPPL/MonitorTool.Gen2
Antiy-AVLTrojan[Monitor]/Win32.PowerSpy
KingsoftWin32.Troj.Undef.a
MicrosoftMonitoringTool:Win32/PowerSpy
XcitiumMalware@#3czwrpgwf7iwh
ArcabitApplication.PowerSpy.BM
ZoneAlarmnot-a-virus:Monitor.Win32.PowerSpy.fee
GDataWin32.Application.PowerSpy.B
CynetMalicious (score: 99)
BitDefenderThetaAI:Packer.6774F65D1C
ALYacApplication.PowerSpy.BM
Cylanceunsafe
RisingSpyware.VB!8.226 (CLOUD)
YandexTrojan.GenAsa!X8I3fMgWdxU
IkarusMonitoringTool
MaxSecureTrojan.Malware.4295710.susgen
FortinetW32/VB.GNFZ!tr
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)
alibabacloudTrojan[spy]:Win/PowerSpy.fee

How to remove Application.PowerSpy.BM?

Application.PowerSpy.BM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment