Trojan

Trojan.Win32.Bingoml.cuuv removal guide

Malware Removal

The Trojan.Win32.Bingoml.cuuv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Bingoml.cuuv virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup

How to determine Trojan.Win32.Bingoml.cuuv?


File Info:

name: 5CC606DA201B13621D8F.mlw
path: /opt/CAPEv2/storage/binaries/ac09191a764be01ddb2de5b11029b5c57cc6cbc59640aff77100d5ad8d70d5ad
crc32: B8CF5041
md5: 5cc606da201b13621d8f5eed0831586f
sha1: f0c021f05208f7d8c4877eeea2442659d95ea11f
sha256: ac09191a764be01ddb2de5b11029b5c57cc6cbc59640aff77100d5ad8d70d5ad
sha512: c6906856aa6e37619beb87ab0b8b8ab0afaaa749c5885811f5ceae79e3a4fc0646ee6bd2000eb46128a9e427b0e2a390104a2168bf83e9c2dada4ca84c43e1c0
ssdeep: 24576:cf0DKVuRsXuu2+kz8NVRKkyqwyVTjo/2:cf2KVuaD2+wOYZqwgs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15BF423CDC51109A5E43C3D7AE7CCC09DA082D23E2AFE9B2D65D1CE6904F68F5859AE13
sha3_384: c18d0c92cc30895726a80a60dee4e68bb3c00e0d9a454619233e47f80eb2da21f0fa837abbf1ebb0870ad68bd5270de8
ep_bytes: 60be00d043008dbe0040fcff57eb0b90
timestamp: 2012-01-13 03:38:49

Version Info:

0: [No Data]

Trojan.Win32.Bingoml.cuuv also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Bingoml.4!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop19.13129
MicroWorld-eScanTrojan.GenericKD.47600209
FireEyeGeneric.mg.5cc606da201b1362
ALYacTrojan.GenericKD.47600209
CylanceUnsafe
K7AntiVirusTrojan ( 005239691 )
AlibabaTrojan:Win32/Bingoml.32a59d6f
K7GWTrojan ( 005239691 )
Cybereasonmalicious.05208f
BitDefenderThetaGen:NN.ZexaF.34084.WmGfaW9AqOpb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.NoobyProtect.G suspicious
TrendMicro-HouseCallTROJ_GEN.R002H07L821
Paloaltogeneric.ml
KasperskyTrojan.Win32.Bingoml.cuuv
BitDefenderTrojan.GenericKD.47600209
SUPERAntiSpywareHeur.Agent/Gen-GalPic
AvastWin32:RATX-gen [Trj]
Ad-AwareTrojan.GenericKD.47600209
SophosMal/EncPk-ND
ComodoTrojWare.Win32.Amtar.KNB@4wlm66
EmsisoftTrojan.GenericKD.47600209 (B)
IkarusPUA.NoobyProtect
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASBOL.C6B4
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Packed.NoobyProtect.B
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4826901
McAfeeArtemis!5CC606DA201B
MalwarebytesMalware.AI.4220397340
APEXMalicious
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
AVGWin32:RATX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan.Win32.Bingoml.cuuv?

Trojan.Win32.Bingoml.cuuv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment