Fake Trojan

BScope.Trojan.FakeAV.8113 (file analysis)

Malware Removal

The BScope.Trojan.FakeAV.8113 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Trojan.FakeAV.8113 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine BScope.Trojan.FakeAV.8113?


File Info:

name: 9ECE6EDDAAF7D032E88C.mlw
path: /opt/CAPEv2/storage/binaries/f5dd82ef5dd2f9d9833f0c12c98c5567c7ad2d78791087a6b07e5e796e700853
crc32: A57A861E
md5: 9ece6eddaaf7d032e88cb17cf308598e
sha1: d52c7d7b545a85b20444eac0e9fc2003cb41b8fa
sha256: f5dd82ef5dd2f9d9833f0c12c98c5567c7ad2d78791087a6b07e5e796e700853
sha512: 4dd04670268db75fb511a54ea5978c1dcf02bc6e8ac07426581f1d01de8c088797a0c466ae91ba55c2ff76f72532d3dc069d75962705c9ccb93096d6f98a0ec7
ssdeep: 12288:rtm/4mZPKCDFPGod1oN6/YCPO44z64Qo5n3sjYrMidlgkgD:r0/4sP3FGMoNbC56VvETkM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19AF423B2438990F8D89EA9B097ABC639B1DBFD0D059CDB0490B7FB1C973A354AD64053
sha3_384: 0f835c524c795b2c91c9f371f15513fa1d87f33290f2d8604c8651f0ccf22e8b36405799ffe9b20e324d67a893b9edb4
ep_bytes: 68004040005f8d35f02f40006a1d59f3
timestamp: 2012-08-31 23:11:12

Version Info:

0: [No Data]

BScope.Trojan.FakeAV.8113 also known as:

BkavW32.AIDetectMalware
CAT-QuickHealTrojan.Lethic.B
ALYacTrojan.VIZ.Gen.1
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f2c01 )
BitDefenderTrojan.VIZ.Gen.1
K7GWTrojan ( 0040f2c01 )
Cybereasonmalicious.daaf7d
BaiduWin32.Trojan.Kryptik.ur
VirITTrojan.Win32.Crypt_s.ADD
CyrenW32/FakeAlert.WP.gen!Eldorado
SymantecSecShieldFraud!gen10
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.ARUZ
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.FakeAV.bfyosg
MicroWorld-eScanTrojan.VIZ.Gen.1
AvastWin32:FakeAlert-DCG [Trj]
RisingTrojan.Kryptik!1.A81D (CLASSIC)
EmsisoftTrojan.VIZ.Gen.1 (B)
F-SecureTrojan.TR/Winwebsec.ioinw
DrWebBackDoor.Slym.1375
VIPRETrojan.VIZ.Gen.1
TrendMicroWORM_KELIHOS.SMB
McAfee-GW-EditionBehavesLike.Win32.Glupteba.bc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.9ece6eddaaf7d032
SophosMal/Zbot-KR
IkarusTrojan-PSW.Win32.Tepfer
JiangminTrojan/Tepfer.Gen
WebrootW32.Rogue.Gen
AviraTR/Winwebsec.ioinw
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftBackdoor:Win32/Kelihos.F
XcitiumTrojWare.Win32.Kryptik.ARLI@4t2kfq
ArcabitTrojan.VIZ.Gen.1
SUPERAntiSpywareTrojan.Agent/Gen-RogueRel
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.VIZ.Gen.1
GoogleDetected
AhnLab-V3Trojan/Win32.Tepfer.R48460
Acronissuspicious
McAfeeBackDoor-FJW
VBA32BScope.Trojan.FakeAV.8113
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Tepfer.B
TrendMicro-HouseCallWORM_KELIHOS.SMB
TencentWin32.Trojan.Generic.Ncnw
YandexTrojan.GenAsa!nU3DF3gNMw8
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.X!tr
BitDefenderThetaGen:NN.ZexaF.36350.UqW@aGuAPvf
AVGWin32:FakeAlert-DCG [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove BScope.Trojan.FakeAV.8113?

BScope.Trojan.FakeAV.8113 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment