PUA

What is “Win32:Radmin-BV [PUP]”?

Malware Removal

The Win32:Radmin-BV [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Radmin-BV [PUP] virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Starts servers listening on 0.0.0.0:1313
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Win32:Radmin-BV [PUP]?


File Info:

name: EF7881E1AAC03494CDC3.mlw
path: /opt/CAPEv2/storage/binaries/4192ef73097d5d12bfa80d9867d3f8be012d7e961561d3781a0f754422a85395
crc32: CF1C910F
md5: ef7881e1aac03494cdc382b48e025150
sha1: ae63e3e38cb93e553de7e689d3b35b2a8027be23
sha256: 4192ef73097d5d12bfa80d9867d3f8be012d7e961561d3781a0f754422a85395
sha512: 68a9dc13756ace171c0a4f982fd774e280748ee981331f9f188ae3c1989124ecd2f47698b77aa4f48e6bc00f59bee215219828120ac7038361b740ba2f122d34
ssdeep: 6144:sb01UiTy+SGPQTnB0RA//xWO5KvSDrhYTHGKJz:4piTy+UWA//xWhKrSpJz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15B440221F6F1C5F9E4A316314D413FA563BAEAB40B2D848363884C09AF756CADA3D357
sha3_384: adfd270f892b2433397315d730c0d5d4448d55f00b080062eee3b89b17294606b6799a5d497f804e4843c3add113e3df
ep_bytes: 558bec6aff68285e410068202f410064
timestamp: 2011-01-07 07:06:28

Version Info:

CompanyName: Oleg N. Scherbakov
FileDescription: 7z Setup SFX (x86)
FileVersion: 1.5.0.1989
InternalName: 7ZSfxMod
LegalCopyright: Copyright © 2005-2011 Oleg N. Scherbakov
OriginalFilename: 7ZSfxMod_x86.exe
PrivateBuild: January 7, 2011
ProductName: 7-Zip SFX
ProductVersion: 1.5.0.1989
Translation: 0x0000 0x04b0

Win32:Radmin-BV [PUP] also known as:

LionicTrojan.Win32.Reconyc.4!c
DrWebProgram.RemoteAdmin.75
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Reconyc.2805f76f
K7GWRiskware ( 0040eff71 )
SymantecTrojan.Gen.6
TrendMicro-HouseCallTROJ_GEN.R002H0CKQ21
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-1062762
KasperskyTrojan.Win32.Agentb.kpvp
NANO-AntivirusRiskware.Win32.RAdmin.gbau
AvastWin32:Radmin-BV [PUP]
RisingTrojan.Generic@ML.100 (RDMK:0/kaxpTRJCKl8yxBC2mVBg)
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
MaxSecureTrojan.Malware.73474710.susgen
AviraTR/AD.Allaple.nbtos
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
McAfeeArtemis!EF7881E1AAC0
VBA32Trojan.Reconyc
MalwarebytesTrojan.Agent
APEXMalicious
eGambitGeneric.Malware
FortinetMalicious_Behavior.SB
AVGWin32:Radmin-BV [PUP]

How to remove Win32:Radmin-BV [PUP]?

Win32:Radmin-BV [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment