Trojan

How to remove “Trojan.Win32.Cosmu.byjv”?

Malware Removal

The Trojan.Win32.Cosmu.byjv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Cosmu.byjv virus can do?

  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Win32.Cosmu.byjv?


File Info:

name: B739342D41F7AE108D61.mlw
path: /opt/CAPEv2/storage/binaries/b387a333e4ecea4aed95f2885ecfa8854a1b4fa03387fccf6d09f45a23f6eba4
crc32: 87C622EE
md5: b739342d41f7ae108d617b76ef2c3541
sha1: 194062b5a58547d00d0d1f7f6b750c8f44513cf2
sha256: b387a333e4ecea4aed95f2885ecfa8854a1b4fa03387fccf6d09f45a23f6eba4
sha512: aacfc97fc799639fd777cd872781c818cc1677d09ec266aeac21a66b7cf5798328cbcad27860516375e1403ca273f425ca1d0c59f6b08dc827f21c48e6b1e9e9
ssdeep: 196608:qQCJNT7uU/eBwrlWgl4AYlRX+OowMAx8ROOFGospC9YEmW6RKP6VJrhBe:qPNv/gotStMAx8RXFmEeEmW68CVJ9Be
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T171D633EBB276BFD2D06F07B24BDF4939C493F30BD9EA610876CAD910B942135646061B
sha3_384: e3a3e75021f303cf8995b8409695d2fcee146ea83d9aeb2f7a8dc6e67d067dd0daa4831c1cc232b5e2512d461766691f
ep_bytes: 60be006041008dbe00b0feff5783cdff
timestamp: 2003-05-15 08:43:10

Version Info:

0: [No Data]

Trojan.Win32.Cosmu.byjv also known as:

LionicTrojan.Win32.Cosmu.4!c
FireEyeTrojan.GenericKD.4363641
ALYacTrojan.GenericKD.4363641
CylanceUnsafe
ZillyaTrojan.Cosmu.Win32.13499
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Cosmu.8c00b9d5
K7GWRiskware ( 0040eff71 )
SymantecTrojan.Gen.2
TrendMicro-HouseCallTROJ_GEN.R002H07G421
AvastFileRepMalware [PUP]
KasperskyTrojan.Win32.Cosmu.byjv
BitDefenderTrojan.GenericKD.4363641
NANO-AntivirusTrojan.Win32.Cosmu.elmtum
EmsisoftTrojan.GenericKD.4363641 (B)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
SophosMal/Generic-S
JiangminTrojan/Cosmu.qlq
WebrootW32.Malware.Ml.Vt
AviraWORM/Cosmu.cxwew
GridinsoftRansom.Win32.Occamy.sa
MicrosoftTrojan:Win32/Occamy.CB3
GDataTrojan.GenericKD.4363641
McAfeeArtemis!B739342D41F7
MAXmalware (ai score=83)
VBA32Trojan.Cosmu
RisingTrojan.Cosmu!8.2B2 (CLOUD)
YandexTrojan.Cosmu!zPVMmVgC6RI
FortinetPossibleThreat
AVGFileRepMalware [PUP]
Cybereasonmalicious.d41f7a

How to remove Trojan.Win32.Cosmu.byjv?

Trojan.Win32.Cosmu.byjv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment