Trojan

Trojan.Win32.Bsymem.aoac removal instruction

Malware Removal

The Trojan.Win32.Bsymem.aoac is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Bsymem.aoac virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Transacted Hollowing
  • Creates a copy of itself
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics

How to determine Trojan.Win32.Bsymem.aoac?


File Info:

name: 0089D664BDA16B414FB6.mlw
path: /opt/CAPEv2/storage/binaries/331f466b1e5915b4f8efe2267857fe68427b9b647c95d1280c47367d60327e13
crc32: 406F1CB8
md5: 0089d664bda16b414fb638d78896a267
sha1: 6f9fbc6beb9c12b6c1eedd447d3d89100b0c22f6
sha256: 331f466b1e5915b4f8efe2267857fe68427b9b647c95d1280c47367d60327e13
sha512: 9ddae16f953ce65b13f1d631c1891a952de1773bdf111323f564e13675934a74abe69d2495f49c2a76caca857c10536d24d5ff139207513f0601d3b13170ceff
ssdeep: 1536:1QZpnFOsxdaRny615cpdcnri1q6cdNLjkb+xU+F3vPgTS1ySIydogA2876M7Pf:1QZvOsPPKedcrbdJIMSvX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16ED3B473A5857991D35218B1DDB3F26252E02D284B7F04026E1F3FBE2F3DDA64939682
sha3_384: 2b57f2e70d306c0f8183666dd0bbbc0997cd572804de240a60605b7414207aff5b0c7fe86388fcf388dbcf402a270c04
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2016-12-11 21:50:38

Version Info:

0: [No Data]

Trojan.Win32.Bsymem.aoac also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Bsymem.4!c
MicroWorld-eScanTrojan.GenericKD.68969267
FireEyeTrojan.GenericKD.68969267
McAfeeArtemis!0089D664BDA1
ZillyaTrojan.Bsymem.Win32.4110
CrowdStrikewin/grayware_confidence_60% (W)
SymantecTrojan.Gen.MBT
KasperskyTrojan.Win32.Bsymem.aoac
BitDefenderTrojan.GenericKD.68969267
TencentWin32.Trojan.Bsymem.Bdhl
EmsisoftTrojan.GenericKD.68969267 (B)
F-SecureTrojan.TR/Bsymem.hcfxt
DrWebTrojan.MulDrop20.42225
VIPRETrojan.GenericKD.68969267
TrendMicroTROJ_GEN.R002C0XHS23
McAfee-GW-EditionBehavesLike.Win32.Dropper.cm
Trapminemalicious.moderate.ml.score
GDataTrojan.GenericKD.68969267
AviraTR/Bsymem.hcfxt
ArcabitTrojan.Generic.D41C6333
ZoneAlarmTrojan.Win32.Bsymem.aoac
ALYacTrojan.GenericKD.68969267
MAXmalware (ai score=80)
TrendMicro-HouseCallTROJ_GEN.R002C0XHS23
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Bsymem.aoac?

Trojan.Win32.Bsymem.aoac removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment