Trojan

What is “BScope.Trojan.IRCbot”?

Malware Removal

The BScope.Trojan.IRCbot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Trojan.IRCbot virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine BScope.Trojan.IRCbot?


File Info:

name: 143C4719FFFF9C1055D2.mlw
path: /opt/CAPEv2/storage/binaries/0daca49ab5644ca9536cecd3de942220d76ff0536d5f8eb942c49be17df70ed6
crc32: B9F0F2D4
md5: 143c4719ffff9c1055d2cf5b193db508
sha1: 3c89ee874d083295823c9a1dc82874bd2c228718
sha256: 0daca49ab5644ca9536cecd3de942220d76ff0536d5f8eb942c49be17df70ed6
sha512: 2c9c68da28671b8bc73248814891142f92e5f43fd7e5ed84cbcf9be778de76116de6ab37da780c6294f7d9030a3d0ae6ab6e96e1e1e9fcd71fc09b226dc28718
ssdeep: 6144:szZhKcV6HK01CiR24MxuCyhFaQAMSqgyTDB0XYbXP6jlLdkT/jmZdI8WrJtQw3LG:szZByp24OyhFaQAMSqgyTDB0XYbXP6BH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18C44AF57F3940EB2DEC358B94866233FAA33D258EF2191D3E3C42D0996521D16E3E792
sha3_384: 5139d17e276c1f25cad9391ead4f7e91532c7d9aaf23205abf2b7aadaf12a0f0ad26dbd182283990d28f258d18ed845f
ep_bytes: 681000000068000000006898024400e8
timestamp: 2022-01-29 09:56:12

Version Info:

0: [No Data]

BScope.Trojan.IRCbot also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Skillis.lqzG
FireEyeGeneric.mg.143c4719ffff9c10
McAfeeGenericRXRH-AN!143C4719FFFF
CylanceUnsafe
SangforSuspicious.Win32.Attribute.HighConfidence
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/FakeAlert.TD.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazr4RKXCO7kwrqCGoIFaPZ1b)
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SentinelOneStatic AI – Suspicious PE
SUPERAntiSpywareTrojan.Agent/Gen-Graftor
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
BitDefenderThetaGen:NN.ZexaF.34182.puW@aas3A9bi
VBA32BScope.Trojan.IRCbot
TrendMicro-HouseCallTROJ_GEN.R002H06AT22
MaxSecureTrojan.Malware.300983.susgen

How to remove BScope.Trojan.IRCbot?

BScope.Trojan.IRCbot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment