Trojan

Trojan.Heur.bu0bsSV0Ifkb removal tips

Malware Removal

The Trojan.Heur.bu0bsSV0Ifkb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Heur.bu0bsSV0Ifkb virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Authenticode signature is invalid
  • Creates a hidden or system file
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempted to write directly to a physical drive
  • Harvests cookies for information gathering
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.Heur.bu0bsSV0Ifkb?


File Info:

name: B2F60B457F80B9A95413.mlw
path: /opt/CAPEv2/storage/binaries/37ae7ca3235584124328b216bcee112e624d58422c6f3d9dbb0bafbd207bf087
crc32: ADFA7D5B
md5: b2f60b457f80b9a954131f0f12e8abe3
sha1: 41194760e35cba608c9f84202c52fd5319e37e6d
sha256: 37ae7ca3235584124328b216bcee112e624d58422c6f3d9dbb0bafbd207bf087
sha512: 343a313113596787f82ee4ccadaddeb3c8479ad358b816e29b8e42b383ec599e45004556a7881848a2f85926c03bad274d16bd264baf0b7de73a33eba785bc13
ssdeep: 6144:K2EGyyn8t8qgCJsEIrELgoNPrpO7LIyPLldmbvuXMjR1y9lZpi:KYqgNEIrEkoNk7L6zSZpi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17A847C1176D08436F1B32876497E9624AA79B8701F21C2CF77D01A2F9E717D2EA3172B
sha3_384: 9d7e29808b83e68f04b7c623c5c52e10f50729b4a55fb25e0b2a69aecf8dd45a6b97af1b7b4b682c2617e7736660c4e3
ep_bytes: e860980000e979feffff8bff558bec83
timestamp: 2013-11-21 16:57:18

Version Info:

CompanyName: Adobe Systems Incorporated
EnglishName: English
FileDescription: Adobe Reader and Acrobat Manager Helper
FileVersion: 1.701.3.3014
LanguageId: 0409
LegalCopyright: Copyright 2013 Adobe Systems Incorporated
ProductVersion: 1.701.3.3014
Translation: 0x0409 0x04e4

Trojan.Heur.bu0bsSV0Ifkb also known as:

DrWebWin32.HLLW.Autoruner.547
MicroWorld-eScanGen:Trojan.Heur.bu0bsSV0Ifkb
FireEyeGen:Trojan.Heur.bu0bsSV0Ifkb
ALYacGen:Trojan.Heur.bu0bsSV0Ifkb
Cybereasonmalicious.57f80b
BitDefenderThetaAI:Packer.7E9418C81C
CyrenW32/Agent.CTM.gen!Eldorado
TrendMicro-HouseCallWORM_AUTORUN.BGA
Paloaltogeneric.ml
ClamAVWin.Worm.Vindor-9886047-0
BitDefenderGen:Trojan.Heur.bu0bsSV0Ifkb
AvastWin32:Malware-gen
SophosGeneric ML PUA (PUA)
TrendMicroWORM_AUTORUN.BGA
McAfee-GW-EditionRDN/Autorun.worm.gen
EmsisoftGen:Trojan.Heur.bu0bsSV0Ifkb (B)
MaxSecureTrojan.Malware.121218.susgen
MAXmalware (ai score=85)
MicrosoftTrojan:Win32/Tiggre!rfn
ViRobotWorm.Win32.Z.Autorun.379822
GDataGen:Trojan.Heur.bu0bsSV0Ifkb
AhnLab-V3Worm/Win.Autorun.C4798986
McAfeeRDN/Autorun.worm.gen
VBA32Worm.AutoRun
MalwarebytesMalware.AI.3696146603
RisingWorm.VB!1.DA41 (CLASSIC)
YandexWorm.AutoRun!5vaUR4njuNo
IkarusTrojan.Dropper
FortinetW32/AUTORUN.BGA!worm
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Trojan.Heur.bu0bsSV0Ifkb?

Trojan.Heur.bu0bsSV0Ifkb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment