Trojan

How to remove “Trojan:Win32/CommandAndControl!BV”?

Malware Removal

The Trojan:Win32/CommandAndControl!BV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/CommandAndControl!BV virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings

How to determine Trojan:Win32/CommandAndControl!BV?


File Info:

crc32: 84DEE00D
md5: 65714499e3ac6ca88250bd788d544d2c
name: 65714499E3AC6CA88250BD788D544D2C.mlw
sha1: 7bacbd736a45450981b2b02045d18139d4d6fbc6
sha256: b3e6261864a914a95201e31319eab0a631f8afa6ad29d6e84fa54a66627682ac
sha512: 19d8c40e346d3c350a808d22d6707806afbb3639750e307a643b2762afbfe34fab0b1e2e70dec66bb9a616a1d0ac47b1bbbd729053f3d279b9ce34f755f9e3d9
ssdeep: 24576:lOt5ugSbeSpotiwGR6943mopVTt89hT0iOnkr7:euWC7Ty9hT0Znkr7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2016 Spiritsoft All Rights Reserved.
InternalName: ipts.exe
FileVersion: 2019.11.25.35
CompanyName: Spiritsoft
Comments: Traffic Spirit(35)
ProductName: Traffic Spirit
ProductVersion: 6.5.2.35
FileDescription: Traffic Spirit
OriginalFilename: ipts.exe
Translation: 0x0409 0x04b0

Trojan:Win32/CommandAndControl!BV also known as:

K7AntiVirusUnwanted-Program ( 0050c3511 )
MicroWorld-eScanGen:Variant.Ulise.89744
CAT-QuickHealTrojan.Mauvaise.S333040
ALYacGen:Variant.Strictor.232993
CylanceUnsafe
K7GWUnwanted-Program ( 0050c3511 )
CyrenW32/Trojan.JAOF-6527
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FlowSpirit.N potentially unsafe
AvastWin32:Malware-gen
GDataGen:Variant.Ulise.89744
Kasperskynot-a-virus:HEUR:NetTool.Win32.TrafficExchange.gen
BitDefenderGen:Variant.Ulise.89744
Ad-AwareGen:Variant.Ulise.89744
SophosGeneric PUA HL (PUA)
BitDefenderThetaGen:NN.ZexaF.32515.cD0@aG8s7sij
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
FireEyeGen:Variant.Ulise.89744
SentinelOneDFI – Suspicious PE
Endgamemalicious (high confidence)
WebrootPua.Trafficspirit
MicrosoftTrojan:Win32/CommandAndControl!BV
JiangminNetTool.TrafficExchange.a
ArcabitTrojan.Ulise.D15E90
AegisLabRiskware.Win32.TrafficExchange.1!c
ZoneAlarmnot-a-virus:HEUR:NetTool.Win32.TrafficExchange.gen
McAfeePUP-XFX-BX
MAXmalware (ai score=86)
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0PKS19
RisingTrojan.Generic@ML.100 (RDMK:V4MP53TYGR0OUNa5COz3/g)
FortinetRiskware/TrafficExchange
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Virus.NetTool.8e0

How to remove Trojan:Win32/CommandAndControl!BV?

Trojan:Win32/CommandAndControl!BV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment