Malware

BScope.Malware-Cryptor.Win32.Vals.22 removal tips

Malware Removal

The BScope.Malware-Cryptor.Win32.Vals.22 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Malware-Cryptor.Win32.Vals.22 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine BScope.Malware-Cryptor.Win32.Vals.22?


File Info:

name: 956155A4643C5EAE47F2.mlw
path: /opt/CAPEv2/storage/binaries/6d0cba7b030de4beba23f644a1efc47e5cc426d4c27fdf8d7238d6f60e27227d
crc32: E881B3DC
md5: 956155a4643c5eae47f2435913664cd2
sha1: 75ba5ae3f47629bc423dfaaef08a3f1b2e319032
sha256: 6d0cba7b030de4beba23f644a1efc47e5cc426d4c27fdf8d7238d6f60e27227d
sha512: f58c28753db1c535436b481ff5dbc4c2becae830aeb6266254075595aa919308f19ef16bdbe328fd9d812b2db5918b5d3afa211e7dd0f9af73133eedccc9da58
ssdeep: 12288:9DG3Huf86CD+YX/clr3z3OtF3VQVBxZM9kyDHIB9NvZebEOJqFcdkr+CCqp5cjZ3:9wH02+Eq3z3OtpVyPM1DHIBwQFcdmFPg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T198D423AFD9B84669C5D19D76E0B11D7FFE9D4102385045EA8B20CE226CC148FB7A837A
sha3_384: 4a5f4ea5060838dfec631ab17af8813800b73eeed9d6568d0d32f92ab688cda9a76dd2014d77b3c052903b8e4256198f
ep_bytes: 66b8020066ba05006683c0ff6681d209
timestamp: 2007-12-10 17:49:50

Version Info:

0: [No Data]

BScope.Malware-Cryptor.Win32.Vals.22 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.kYTZ
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.956155a4643c5eae
McAfeeGeneric PWS.d
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.102
SangforSuspicious.Win32.Save.a
AlibabaTrojanPSW:Win32/BScope.22e72a5e
Cybereasonmalicious.4643c5
VirITTrojan.Win32.Generic.UPM
CyrenW32/Trojan.RONH-8545
SymantecInfostealer
ESET-NOD32Win32/Spy.Zbot.JF
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-4531
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.720254
NANO-AntivirusTrojan.Win32.Zbot.euzyl
MicroWorld-eScanGen:Variant.Razy.720254
AvastWin32:Zbot-MNG [Trj]
TencentMalware.Win32.Gencirc.10b88cfa
Ad-AwareGen:Variant.Razy.720254
EmsisoftGen:Variant.Razy.720254 (B)
ComodoTrojWare.Win32.Spy.Zbot.rpe0@1cu8qp
DrWebTrojan.PWS.Panda.114
VIPRETrojan-Spy.Win32.Zbot.gen (v)
TrendMicroTSPY_ZBOT.SMRC
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
SophosMal/Generic-R + Mal/Zbot-O
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Spy.Zbot.DT
JiangminTrojanSpy.Zbot.his
WebrootW32.Malware.Gen
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.630F3F
ArcabitTrojan.Razy.DAFD7E
ViRobotTrojan.Win32.Zbot.66560.CA
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Zbot.UR!MTB
AhnLab-V3Spyware/Win32.Zbot.R1268
Acronissuspicious
BitDefenderThetaAI:Packer.F591AB6D1E
ALYacGen:Variant.Razy.720254
TACHYONTrojan-Spy/W32.ZBot.634368.G
VBA32BScope.Malware-Cryptor.Win32.Vals.22
TrendMicro-HouseCallTSPY_ZBOT.SMRC
RisingTrojan.Win32.Nodef.fga (CLOUD)
YandexTrojanSpy.Zbot!iFzfE/w5scM
IkarusTrojan-Spy.Win32.Zbot
MaxSecureTrojan.Malware.1141840.susgen
FortinetW32/Zbot.BCW!tr.bdr
AVGWin32:Zbot-MNG [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove BScope.Malware-Cryptor.Win32.Vals.22?

BScope.Malware-Cryptor.Win32.Vals.22 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment