Trojan

Trojan:Win32/Bumat!rfn information

Malware Removal

The Trojan:Win32/Bumat!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Bumat!rfn virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Spanish (Modern)
  • The binary likely contains encrypted or compressed data.
  • Sniffs keystrokes
  • Checks for the presence of known windows from debuggers and forensic tools
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Bumat!rfn?


File Info:

crc32: 2D22A2F4
md5: 482c39e218ec6f524180b6a06a4684db
name: Serious-Sam-HD-The-Second-Encounter-v1.1-10-Trainer.exe
sha1: 69b96cb85ce7b738488727c82234b66be8cce2fd
sha256: 13aa58decb7ab25277bb0ff76dbef024b6c1d9374492e4500c0b1dc69283daf3
sha512: 600ad3592e15821840bd860b8a8a42e002b826a1ce9ad6f90dcc3b6d9eacd17f6d6c6d9ae5f97bc6ef446d52f2d72d1bb5043d08b559d803c14693670f9c1923
ssdeep: 12288:TCuO9tGAxT+cJFQJEeOK/Z9vHkdJqykZAvmR0gm3bzB7g9Kg1NTjCzxe8M2FXaq0:TCusd/LK/nHNyuZmPBfgL+gJyaqikg
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

LegalCopyright: www.sicheats.com
InternalName: SC Engine Trainer
FileVersion: 2.3.1.2388
CompanyName: www.sicheats.com
LegalTrademarks: www.sicheats.com
Comments: www.sicheats.com
ProductName: www.sicheats.com
ProductVersion: 2.3
SC Engine Homepage: http://www.sicheats.com/
FileDescription: SC Engine Trainer
Thanks to: DarkByte
OriginalFilename: SC Trainer
Description: SC Engine Trainer
Translation: 0x040a 0x04e4

Trojan:Win32/Bumat!rfn also known as:

MicroWorld-eScanTrojan.Generic.4170845
FireEyeTrojan.Generic.4170845
McAfeeArtemis!482C39E218EC
CylanceUnsafe
ZillyaTrojan.VkHost.Win32.345
K7AntiVirusHacktool ( 0048bc581 )
BitDefenderTrojan.Generic.4170845
K7GWHacktool ( 0048bc581 )
Cybereasonmalicious.218ec6
TrendMicroTROJ_GEN.F43EZK8
F-ProtW32/MalwareF.EFSI
APEXMalicious
ClamAVWin.Trojan.Vkhost-553
GDataTrojan.Generic.4170845
AlibabaHackTool:Win32/CheatEngine.ff260694
AegisLabTrojan.Win32.Generic.4!c
RisingTrojan.Bumat!8.710 (CLOUD)
Endgamemalicious (moderate confidence)
SophosCheatEngine (PUA)
ComodoMalware@#33oy7lle05bux
F-SecureTrojan.TR/VKHost.ajy
VIPRETrojan.Win32.Delf.abt (fs)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.PUP.cc
MaxSecureTrojan.Malware.464766.susgen
EmsisoftTrojan.Generic.4170845 (B)
IkarusTrojan-PWS.Win32.VKont
CyrenW32/Risk.QPOS-1256
JiangminTrojan/AdwareRemover.n
WebrootW32.Malware.Gen
AviraTR/VKHost.ajy
MAXmalware (ai score=99)
MicrosoftTrojan:Win32/Bumat!rfn
ArcabitTrojan.Generic.D3FA45D
ALYacTrojan.Generic.4170845
TACHYONTrojan/W32.VkHost.916622
PandaTrj/CI.A
ESET-NOD32a variant of Win32/HackTool.CheatEngine.AB potentially unsafe
TrendMicro-HouseCallTROJ_GEN.F43EZK8
TencentWin32.Trojan.Gen.Pbpk
YandexHackTool.CheatEngine!4HkJM0juWSc
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetRiskware/CheatEngine
Ad-AwareTrojan.Generic.4170845

How to remove Trojan:Win32/Bumat!rfn?

Trojan:Win32/Bumat!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment