Trojan

BScope.Trojan.Kraplick.vck removal tips

Malware Removal

The BScope.Trojan.Kraplick.vck is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Trojan.Kraplick.vck virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine BScope.Trojan.Kraplick.vck?


File Info:

crc32: FA4F0F6A
md5: 6f9667694c9c3294cdc6b2afc0809623
name: 6F9667694C9C3294CDC6B2AFC0809623.mlw
sha1: 3d2e6231d233f0f882bbbb52c4e50c1aa3be0ed2
sha256: 585ce567af68a001be2b8e70096c1463f0c862543555e9ef93c7b3c7d0c89034
sha512: 223cd34f740379c58ac42d3fac23b7fabf262125a310231c2995db8754fe86e866f1c1d71a36f5972028a246645e694dc04829f0d3af59f13dbd3ebe71c21c54
ssdeep: 49152:T3jDpkqNDsgwnTz0xnd0kNhD5c3IAzIWx:rj1/DsgwTkh9S32W
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

BScope.Trojan.Kraplick.vck also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Packed.846
ALYacGen:Variant.Graftor.754153
CylanceUnsafe
Cybereasonmalicious.94c9c3
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Virbox.C suspicious
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Evo-gen [Susp]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Graftor.754153
MicroWorld-eScanGen:Variant.Graftor.754153
Ad-AwareGen:Variant.Graftor.754153
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34236.uI3@aOy27feb
McAfee-GW-EditionBehavesLike.Win32.Dropper.vh
FireEyeGeneric.mg.6f9667694c9c3294
EmsisoftGen:Variant.Graftor.754153 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen2
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Graftor.754153
MAXmalware (ai score=84)
VBA32BScope.Trojan.Kraplick.vck
RisingTrojan.Generic@ML.96 (RDML:G9jNG9Af9pQDlA6dFh/v2Q)
IkarusPUA.Virbox
AVGWin32:Evo-gen [Susp]

How to remove BScope.Trojan.Kraplick.vck?

BScope.Trojan.Kraplick.vck removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment