Trojan

BScope.TrojanPSW.Cimuz.B removal

Malware Removal

The BScope.TrojanPSW.Cimuz.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.TrojanPSW.Cimuz.B virus can do?

  • At least one process apparently crashed during execution
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Drops a binary and executes it
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the system manufacturer, likely for anti-virtualization
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine BScope.TrojanPSW.Cimuz.B?


File Info:

crc32: A9726BD7
md5: 4ffe209446e475c3802663ac8f4461da
name: server.exe
sha1: 5036744a932ed0a7253fe83035088cb20a41be25
sha256: fab2df7fd7f7574244e9a7cc6ebb1aebcd015afb1b5400b98d6eeeacc5e67a2a
sha512: da702fe4e0ad131aca6ee551210fccc6e9ad3a76ebd0e04dfe2f7ca7b50cee3d489649e8ce515f372b5cbcd68f699e4c909f96dee6830167f3f52c2c53b51ef5
ssdeep: 768:sX0mvrQFZiRigW3BeBPkgkqMptgYToDWzbjDs:sXBrCGigWxaOmiHHs
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

BScope.TrojanPSW.Cimuz.B also known as:

BkavW32.AIDetectVM.malware
DrWebTrojan.Siggen7.25806
MicroWorld-eScanGen:Variant.Ulise.88916
FireEyeGeneric.mg.4ffe209446e475c3
CAT-QuickHealTrojan.Mauvaise.SL1
Qihoo-360Generic/HEUR/QVM07.1.17C1.Malware.Gen
McAfeeGenericRXFT-ZL!4FFE209446E4
CylanceUnsafe
VIPRETrojan.Win32.Redosdru.C (v)
SangforMalware
K7AntiVirusTrojan ( 004b78a51 )
BitDefenderGen:Variant.Ulise.88916
K7GWTrojan ( 004b78a51 )
Cybereasonmalicious.446e47
TrendMicroBKDR_ZEGOST.SM37
BitDefenderThetaAI:Packer.B4D7A47F1E
F-ProtW32/Farfli.CY
ZonerTrojan.Win32.86085
TrendMicro-HouseCallBKDR_ZEGOST.SM37
AvastWin32:BackdoorX-gen [Trj]
ClamAVWin.Malware.Farfli-7101089-0
GDataGen:Variant.Ulise.88916
KasperskyHEUR:Trojan.Win32.Generic
AlibabaBackdoor:Win32/Farfli.228b62e5
NANO-AntivirusTrojan.Win32.AD.erhebd
ViRobotTrojan.Win32.Z.Farfli.36864.CG
AegisLabTrojan.Win32.Generic.4!c
TencentMalware.Win32.Gencirc.10b0cd6d
Ad-AwareGen:Variant.Ulise.88916
SophosMal/Behav-225
ComodoMalware@#ssr2292hm7k1
F-SecureHeuristic.HEUR/AGEN.1044595
ZillyaTrojan.Farfli.Win32.34268
Invinceaheuristic
McAfee-GW-EditionGenericRXFT-ZL!4FFE209446E4
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Ulise.88916 (B)
IkarusTrojan.Win32.Farfli
CyrenW32/Farfli.OIMS-2324
JiangminTrojan.Generic.beksk
WebrootW32.Malware.gen
AviraHEUR/AGEN.1044595
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.AGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.Ulise.D15B54
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Venik!rfn
AhnLab-V3Trojan/Win32.Generic.C2072068
VBA32BScope.TrojanPSW.Cimuz.B
ALYacGen:Variant.Ulise.88916
MalwarebytesBackdoor.Farfli
PandaTrj/Genetic.gen
APEXMalicious
ESET-NOD32Win32/Farfli.BLH
RisingBackdoor.Agent!1.BA39 (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Farfli.CMC!tr
AVGWin32:BackdoorX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.7164915.susgen

How to remove BScope.TrojanPSW.Cimuz.B?

BScope.TrojanPSW.Cimuz.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment