Trojan

About “BScope.Trojan.Danginex” infection

Malware Removal

The BScope.Trojan.Danginex is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Trojan.Danginex virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known devices from debuggers and forensic tools
  • Anomalous binary characteristics

How to determine BScope.Trojan.Danginex?


File Info:

name: 35B6630692E0F8BD981F.mlw
path: /opt/CAPEv2/storage/binaries/2235c2283aad73184869d54dbd9ec59feee3c3d7374024c1013e78496c8331fd
crc32: CFEF0EEB
md5: 35b6630692e0f8bd981fc2a5cdf053ce
sha1: 7e5577611b303b3253671e0e758892d576ab3ee4
sha256: 2235c2283aad73184869d54dbd9ec59feee3c3d7374024c1013e78496c8331fd
sha512: ece7a7c1f0e166bc6654003eb62f780d39e711dc7e3871eea96fa87ab8b182ed7e4f8fb51f7468597dd64c0578b5c5cd4270757ca751585ca909bde3850a17fd
ssdeep: 24576:FRqP5G8BzPkWErqOXfbtiMRgK+cSLsPmxsyzpMOQmXBfrmm:+hzjmqabtNgK+cO+KdpMXmRfym
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T160251206F92D8C48CAD481318453DFA69A11EE06E4B52D76A3F47F8F9E38F17C709169
sha3_384: 445764479695451ba200b3088bfe3acf917dd152619bdaf863c5dc037bb02d14d3815ee6844aea47eb986dbfe58b48ed
ep_bytes: 6801c05700e801000000c3c3e946e97d
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

BScope.Trojan.Danginex also known as:

CynetMalicious (score: 100)
FireEyeGeneric.mg.35b6630692e0f8bd
CylanceUnsafe
VIPRETrojan.Win32.Malware.a
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaPacked:Win32/ASProtect.68d982c6
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Packed.ASProtect.AAB
APEXMalicious
NANO-AntivirusTrojan.Win32.Behav270.bsndyt
ComodoMalware@#192hk48y8d28b
SophosMal/Behav-270
SentinelOneStatic AI – Suspicious PE
KingsoftWin32.Heur.KVM007.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
VBA32BScope.Trojan.Danginex
MalwarebytesMalware.Heuristic.1003
RisingTrojan.Win32.Generic.136E24F7 (C64:YzY0OpXjHM/DK6ka)
IkarusVirus.Win32.Pesin
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Black.D
Cybereasonmalicious.11b303

How to remove BScope.Trojan.Danginex?

BScope.Trojan.Danginex removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment