Categories: Trojan

BScope.Trojan.InstallCube removal

The BScope.Trojan.InstallCube is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Trojan.InstallCube virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Queries information on disks, possibly for anti-virtualization
  • Detects the presence of Wine emulator via registry key
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
ec2-52-29-33-28.eu-central-1.compute.amazonaws.com

How to determine BScope.Trojan.InstallCube?


File Info:

crc32: 5FCF1160md5: a5b073ea770c47b7db5d25bf2c89f38ename: A5B073EA770C47B7DB5D25BF2C89F38E.mlwsha1: 101fbcb779bb918be1c08d4d9c84908a7e04be48sha256: 1a1a7819e6e1cae099bb2615d5757b8512ad41a7ba035440e8d51cdaaaab9cf9sha512: 62dff6686f5855b0a6c512adeb4d620fc926ee7db6bc79bf8ab96ed8c3550ad312322a09464a317a5d843c1f3ff6520df67a27904c3fc3b7889a132105959526ssdeep: 49152:4WCoEpa28ioyCtgnipDVdchPGct4yu5eVhaAl+lRi:ZOP8ptgniRLKPGctxBsfitype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

BScope.Trojan.InstallCube also known as:

Elastic malicious (high confidence)
DrWeb Trojan.InstallCube.2654
MicroWorld-eScan Gen:Variant.Symmi.97524
CAT-QuickHeal Bundler.IcloaderPMF.S19639358
ALYac Gen:Variant.Symmi.97524
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
K7GW Trojan ( 0052512e1 )
K7AntiVirus Trojan ( 0052512e1 )
Cyren W32/S-d48bd7db!Eldorado
ESET-NOD32 a variant of Win32/Kryptik.GCOI
APEX Malicious
Avast Win32:DangerousSig [Trj]
Kaspersky not-a-virus:HEUR:AdWare.Win32.Generic
BitDefender Gen:Variant.Symmi.97524
NANO-Antivirus Riskware.Win32.FileTour.exiuce
Tencent Malware.Win32.Gencirc.11492201
Ad-Aware Gen:Variant.Symmi.97524
Sophos Mal/Generic-S
Comodo ApplicUnwnt@#2libmuo4z92u7
VIPRE FraudTool.Win32.SecurityShield.ek!c (v)
FireEye Generic.mg.a5b073ea770c47b7
Emsisoft Application.AdLoad (A)
SentinelOne Static AI – Malicious PE
Jiangmin AdWare.Generic.svkr
Avira TR/Crypt.XPACK.Gen2
eGambit Unsafe.AI_Score_100%
Arcabit Trojan.Symmi.D17CF4
GData Gen:Variant.Symmi.97524
AhnLab-V3 Adware/Win32.ICLoader.R218849
Acronis suspicious
McAfee Packed-VJ!A5B073EA770C
MAX malware (ai score=81)
VBA32 BScope.Trojan.InstallCube
Malwarebytes Adware.FileTour
Panda Trj/Genetic.gen
Rising Trojan.Kryptik!1.AFA6 (CLASSIC)
Yandex Trojan.GenAsa!F0MKere/ZBg
Ikarus Trojan.Krypt
MaxSecure Adware.ICLoader.gen
Fortinet W32/CoinMiner.GYQC!tr
AVG Win32:DangerousSig [Trj]
Paloalto generic.ml

How to remove BScope.Trojan.InstallCube?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

MSIL/GenKryptik.GXIZ information

The MSIL/GenKryptik.GXIZ is considered dangerous by lots of security experts. When this infection is active,…

4 weeks ago

Malware.AI.2789448175 (file analysis)

The Malware.AI.2789448175 is considered dangerous by lots of security experts. When this infection is active,…

4 weeks ago

Jalapeno.1878 removal instruction

The Jalapeno.1878 is considered dangerous by lots of security experts. When this infection is active,…

4 weeks ago

What is “Trojan.Heur3.LPT.YmKfaKBcBekib”?

The Trojan.Heur3.LPT.YmKfaKBcBekib is considered dangerous by lots of security experts. When this infection is active,…

4 weeks ago

How to remove “Worm.Win32.Vobfus.exmt”?

The Worm.Win32.Vobfus.exmt is considered dangerous by lots of security experts. When this infection is active,…

4 weeks ago

About “TrojanDownloader:Win32/Beebone.JO” infection

The TrojanDownloader:Win32/Beebone.JO is considered dangerous by lots of security experts. When this infection is active,…

4 weeks ago