Trojan

BScope.Trojan.Bamital.1912 removal tips

Malware Removal

The BScope.Trojan.Bamital.1912 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Trojan.Bamital.1912 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine BScope.Trojan.Bamital.1912?


File Info:

name: AC5C70740A53ED4EFE14.mlw
path: /opt/CAPEv2/storage/binaries/8c0bb7b6eb8a6e776abf6836308f37e848fafafdf29dbf35f6973af2e81b7cce
crc32: A01FDC00
md5: ac5c70740a53ed4efe14422fbcaaf495
sha1: ad0edea2c1cfccee39bf7994945d2110d75f5922
sha256: 8c0bb7b6eb8a6e776abf6836308f37e848fafafdf29dbf35f6973af2e81b7cce
sha512: 313744578a56bf8bbea9db2aff46061b05c4ca93cc41b41f581f000d7421f2bfe7352c4bfc85e98f353c0fec5f1e42013eab836080de3d6e3ed169c239919ce1
ssdeep: 49152:gSz3TQdsNGuOh+fxDrOs3cPbwgstF+PQu:78KNGbKNKs3MbzGFe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13EC5AF12F69280F6D60D2530066B7735EA78AA451E35DFC7E374EE3D2D32141E93B22A
sha3_384: 2131314bf4dbde5a3faeccf8272e23961031a14d20b236c0068152ce0b7bc2de3dce9af6224b5737a72a430f852f243d
ep_bytes: 558bec6aff68b0d3650068645b480064
timestamp: 2012-05-17 02:33:47

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

BScope.Trojan.Bamital.1912 also known as:

BkavW32.AIDetectMalware
LionicRiskware.Win32.IMEStartup.1!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.PWSIME.1
ClamAVWin.Dropper.Detected-10008752-0
FireEyeGeneric.mg.ac5c70740a53ed4e
CAT-QuickHealTrojan.Generic.2919
McAfeeArtemis!AC5C70740A53
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
AlibabaRiskWare:Win32/FlyStudio.8a09e222
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.2c1cfc
BitDefenderThetaGen:NN.ZexaF.36738.Is0@aOObD6ob
CyrenW32/OnlineGames.HH.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/FlyStudio.Injector.D potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:RiskTool.Win32.IMEStartup.a
BitDefenderGen:Heur.PWSIME.1
AvastWin32:TrojanX-gen [Trj]
SophosGeneric Reputation PUA (PUA)
F-SecureTrojan:W32/DelfInject.R
VIPREGen:Heur.PWSIME.1
TrendMicroTROJ_GEN.R002C0WIS23
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
Trapminemalicious.moderate.ml.score
EmsisoftApplication.Generic (A)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.15IBL0F
Antiy-AVLTrojan/Win32.FlyStudio.a
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
ArcabitTrojan.PWSIME.1
ZoneAlarmnot-a-virus:UDS:RiskTool.Win32.IMEStartup.a
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
VBA32BScope.Trojan.Bamital.1912
ALYacGen:Heur.PWSIME.1
MAXmalware (ai score=83)
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallTROJ_GEN.R002C0WIS23
RisingHackTool.IMEStartup!8.13A5B (TFE:5:Gc4SWUwPyBF)
IkarusTrojan.Win32.QQWare
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.PHP!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (W)

How to remove BScope.Trojan.Bamital.1912?

BScope.Trojan.Bamital.1912 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment