Trojan

Trojan.Win32.Bsymem.aeft removal tips

Malware Removal

The Trojan.Win32.Bsymem.aeft is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Bsymem.aeft virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • A named pipe was used for inter-process communication
  • Starts servers listening on 127.0.0.1:0
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • CAPE detected the RedLine malware family
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Trojan.Win32.Bsymem.aeft?


File Info:

name: 405ED9A499C847C4A71B.mlw
path: /opt/CAPEv2/storage/binaries/ad5c6edeb433cfad70b84b95f123d967fc4cc74987b5031295f3141ad582753a
crc32: A28EDB88
md5: 405ed9a499c847c4a71b5ead354a5159
sha1: d1cf03d503e3b2f86c5754796345669ef5a1c68b
sha256: ad5c6edeb433cfad70b84b95f123d967fc4cc74987b5031295f3141ad582753a
sha512: e07b6c50c3b3c6ca8f04dc7e74ee94f31c8d6fba6f874948944de7ee06350a73f5bbde7b039ed97f7f8b91a60ff93f03bf31de186fffb836435f3c15574364bc
ssdeep: 12288:VOOfN590uu6opX+t4sPaYwbR51clhCh2LKOga4LTK/:YOfNkuu6oLszQ+lq2u7A/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T133C4F111BAD044B1D572293459F99730A93C7C211F388EDFA3D47A2E5E305C1AB3ABA7
sha3_384: 705d14b136ab815617908c203dd12fadc3b0425b0337f6399e79813f2e7bd983207f05b2c5a5b23e681f34353be80bb1
ep_bytes: e808050000e988feffff3b0d58254300
timestamp: 2020-12-01 18:01:01

Version Info:

0: [No Data]

Trojan.Win32.Bsymem.aeft also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Chapak.trPP
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.105551
FireEyeGeneric.mg.405ed9a499c847c4
ALYacGen:Variant.Midie.105551
CylanceUnsafe
SangforTrojan.Win32.Zenpak.gen
K7AntiVirusTrojan ( 0058ba931 )
AlibabaTrojan:Win32/Bsymem.8fc2c278
K7GWTrojan ( 0058ba931 )
Cybereasonmalicious.503e3b
CyrenW32/Kryptik.FWV.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.HNQD
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Tepfer-9916200-0
KasperskyTrojan.Win32.Bsymem.aeft
BitDefenderGen:Variant.Midie.105551
NANO-AntivirusTrojan.Win32.Zenpak.jjcgox
AvastWin32:CrypterX-gen [Trj]
EmsisoftTrojan.Crypt (A)
DrWebTrojan.PWS.Stealer.31717
TrendMicroTROJ_GEN.R002C0PLA21
SophosMal/Generic-R
IkarusTrojan-Ransom.StopCrypt
GDataWin32.Trojan.BSE.13HWNF8
JiangminTrojan.Zenpak.jhf
WebrootW32.Zenpak
Antiy-AVLTrojan/Generic.ASMalwS.34E9167
GridinsoftRansom.Win32.Sabsik.sa
ViRobotTrojan.Win32.Z.Fragtor.558153
MicrosoftRansom:Win32/StopCrypt.MVK!MTB
CynetMalicious (score: 100)
McAfeeArtemis!405ED9A499C8
MAXmalware (ai score=89)
VBA32BScope.TrojanDropper.Convagent
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTROJ_GEN.R002C0PLA21
RisingTrojan.Generic@ML.100 (RDML:+3NuVxljnNBEv67R2Ykfdw)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.HNQD!tr
BitDefenderThetaGen:NN.ZexaF.34084.wu0@aGAwi0JG
AVGWin32:CrypterX-gen [Trj]
PandaTrj/CI.A

How to remove Trojan.Win32.Bsymem.aeft?

Trojan.Win32.Bsymem.aeft removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment