Categories: Trojan

How to remove “Trojan.Win32.Cosmu.byjv”?

The Trojan.Win32.Cosmu.byjv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Cosmu.byjv virus can do?

  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Win32.Cosmu.byjv?


File Info:

name: B739342D41F7AE108D61.mlwpath: /opt/CAPEv2/storage/binaries/b387a333e4ecea4aed95f2885ecfa8854a1b4fa03387fccf6d09f45a23f6eba4crc32: 87C622EEmd5: b739342d41f7ae108d617b76ef2c3541sha1: 194062b5a58547d00d0d1f7f6b750c8f44513cf2sha256: b387a333e4ecea4aed95f2885ecfa8854a1b4fa03387fccf6d09f45a23f6eba4sha512: aacfc97fc799639fd777cd872781c818cc1677d09ec266aeac21a66b7cf5798328cbcad27860516375e1403ca273f425ca1d0c59f6b08dc827f21c48e6b1e9e9ssdeep: 196608:qQCJNT7uU/eBwrlWgl4AYlRX+OowMAx8ROOFGospC9YEmW6RKP6VJrhBe:qPNv/gotStMAx8RXFmEeEmW68CVJ9Betype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T171D633EBB276BFD2D06F07B24BDF4939C493F30BD9EA610876CAD910B942135646061Bsha3_384: e3a3e75021f303cf8995b8409695d2fcee146ea83d9aeb2f7a8dc6e67d067dd0daa4831c1cc232b5e2512d461766691fep_bytes: 60be006041008dbe00b0feff5783cdfftimestamp: 2003-05-15 08:43:10

Version Info:

0: [No Data]

Trojan.Win32.Cosmu.byjv also known as:

Lionic Trojan.Win32.Cosmu.4!c
FireEye Trojan.GenericKD.4363641
ALYac Trojan.GenericKD.4363641
Cylance Unsafe
Zillya Trojan.Cosmu.Win32.13499
K7AntiVirus Riskware ( 0040eff71 )
Alibaba Trojan:Win32/Cosmu.8c00b9d5
K7GW Riskware ( 0040eff71 )
Symantec Trojan.Gen.2
TrendMicro-HouseCall TROJ_GEN.R002H07G421
Avast FileRepMalware [PUP]
Kaspersky Trojan.Win32.Cosmu.byjv
BitDefender Trojan.GenericKD.4363641
NANO-Antivirus Trojan.Win32.Cosmu.elmtum
Emsisoft Trojan.GenericKD.4363641 (B)
VIPRE Trojan.Win32.Generic!BT
McAfee-GW-Edition BehavesLike.Win32.Dropper.rc
Sophos Mal/Generic-S
Jiangmin Trojan/Cosmu.qlq
Webroot W32.Malware.Ml.Vt
Avira WORM/Cosmu.cxwew
Gridinsoft Ransom.Win32.Occamy.sa
Microsoft Trojan:Win32/Occamy.CB3
GData Trojan.GenericKD.4363641
McAfee Artemis!B739342D41F7
MAX malware (ai score=83)
VBA32 Trojan.Cosmu
Rising Trojan.Cosmu!8.2B2 (CLOUD)
Yandex Trojan.Cosmu!zPVMmVgC6RI
Fortinet PossibleThreat
AVG FileRepMalware [PUP]
Cybereason malicious.d41f7a

How to remove Trojan.Win32.Cosmu.byjv?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Trojan.Varydrop.1392 malicious file

The Trojan.Varydrop.1392 is considered dangerous by lots of security experts. When this infection is active,…

7 mins ago

About “Worm.Win32.Vobfus.dfsc” infection

The Worm.Win32.Vobfus.dfsc is considered dangerous by lots of security experts. When this infection is active,…

13 mins ago

What is “Malware.AI.3968718683”?

The Malware.AI.3968718683 is considered dangerous by lots of security experts. When this infection is active,…

19 mins ago

How to remove “UDS:Trojan-Downloader.JS.SLoad”?

The UDS:Trojan-Downloader.JS.SLoad is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

What is “Malware.AI.521121088”?

The Malware.AI.521121088 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

How to remove “Worm:Win32/Korgo.V”?

The Worm:Win32/Korgo.V is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago