Trojan

What is “Trojan.Win32.Bsymem.kpb”?

Malware Removal

The Trojan.Win32.Bsymem.kpb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Bsymem.kpb virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Bsymem.kpb?


File Info:

crc32: DE7750AE
md5: 98f167b2422ed09afbb3682d3b23418c
name: setup.exe
sha1: 43bae88449d6dd2dffae3df04328504a6e422577
sha256: 1965578865b620d71dbdffa77085fdaa81933bb50d5efcde635096488d32278f
sha512: 45e16315e5430aba12066ce647aebe27b1ee8a4e016d70880ae1cceb80cc2eaf31a8be277861ba70104a210435ecda6f58aa0658d8c625cd2ad7cac76cfe55d8
ssdeep: 196608:/vtAZj41WJ6pzqZjwT6p14pwOYT6y8R+mj0rv8d:nKZ9JozqZjWaBB8wle
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: FitGirl
FileVersion:
CompanyName:
Comments: This installation was built with Inno Setup.
ProductName: Age of Empires 3: CE
ProductVersion:
FileDescription: Age of Empires 3: CE Setup
Translation: 0x0000 0x04b0

Trojan.Win32.Bsymem.kpb also known as:

McAfeeArtemis!98F167B2422E
CylanceUnsafe
AegisLabTrojan.Win32.Bsymem.4!c
SangforMalware
SymantecTrojan.Gen.2
KasperskyTrojan.Win32.Bsymem.kpb
AlibabaTrojan:Win32/Bsymem.810202d2
TencentWin32.Trojan.Bsymem.Hxgb
McAfee-GW-EditionBehavesLike.Win32.BadFile.wc
SophosGeneric PUA ED (PUA)
CyrenW32/Trojan.EISP-4693
MaxSecureTrojan.Malware.74518187.susgen
Antiy-AVLTrojan/Win32.TGeneric
ZoneAlarmTrojan.Win32.Bsymem.kpb
VBA32Trojan.Bsymem
PandaPUP/FreeGames
FortinetW32/Bsymem.KPB!tr

How to remove Trojan.Win32.Bsymem.kpb?

Trojan.Win32.Bsymem.kpb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment