Trojan

What is “BScope.Trojan.MTA.01233”?

Malware Removal

The BScope.Trojan.MTA.01233 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Trojan.MTA.01233 virus can do?

  • Authenticode signature is invalid
  • Creates known Allaple worm mutexes
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine BScope.Trojan.MTA.01233?


File Info:

name: B21F37B9CDFA858855C4.mlw
path: /opt/CAPEv2/storage/binaries/3082c72146679cc798752476f0e1cbdaee6cd7dc639ee7da9fb0795968782f14
crc32: 33B5D7D2
md5: b21f37b9cdfa858855c43e2415724d6c
sha1: 38a3fbcf351d88c10185c20aac81445ca59a113c
sha256: 3082c72146679cc798752476f0e1cbdaee6cd7dc639ee7da9fb0795968782f14
sha512: 367cdc475b33ff6e2dc01a369432fbbd5c2a7e6ad9a27b38429b6abe6c7966196d411ee578dfb3244dea909fcbfea5a232be3733baa146fae8fd5618fd2c4326
ssdeep: 3072:g/Pdl9o/KfWQeOCKWmgXGN69Z2mmpmRj:IlGQROZ2mK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17DB31871E253A426CC75053C974AE3FD8DECEA335704887B9BC8CE262DB4BA1DB12546
sha3_384: 4c909b4d2b6302c385c5e3ddafb1058212bdc6ae1b5f16b408ddb6a2df1260f86e7b6272be7ccea18b828dfc4d83df48
ep_bytes: e8eb0200006803800000e845090000e8
timestamp: 2006-11-28 21:04:54

Version Info:

0: [No Data]

BScope.Trojan.MTA.01233 also known as:

LionicTrojan.Win32.Eb.ts5c
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Dacic.4254EF66.A.A2550686
FireEyeGeneric.mg.b21f37b9cdfa8588
CAT-QuickHealWorm.Allaple.B4
SkyhighBehavesLike.Win32.ExploitDcomRpc.ch
ALYacGeneric.Dacic.4254EF66.A.A2550686
MalwarebytesGeneric.Malware.AI.DDS
VIPREGeneric.Dacic.4254EF66.A.A2550686
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004e40051 )
AlibabaWorm:Win32/Kolab.e8e7
K7GWTrojan ( 004e40051 )
Cybereasonmalicious.f351d8
ArcabitGeneric.Dacic.4254EF66.A.A2550686
BaiduWin32.Worm.Rbot.a
VirITBackdoor.Win32.SdBot.AFCX
SymantecW32.Spybot.Worm
ESET-NOD32a variant of Win32/Allaple.NAC
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Eb.dgo
BitDefenderGeneric.Dacic.4254EF66.A.A2550686
NANO-AntivirusTrojan.Win32.Allaple.bgryk
AvastWin32:Allaple-D [Trj]
TencentTrojan.Win32.Eb.ha
SophosMal/IRCBot-B
F-SecureWorm.WORM/Rbot.Gen
DrWebTrojan.Starman
TrendMicroTROJ_GEN.R002C0CKK23
EmsisoftGeneric.Dacic.4254EF66.A.A2550686 (B)
SentinelOneStatic AI – Malicious PE
JiangminWorm/Generic.zfq
AviraWORM/Rbot.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan[Backdoor]/Win32.Rbot
Kingsoftmalware.kb.a.1000
XcitiumMalCrypt.Indus!@1qrzi1
MicrosoftTrojan:Win32/IRCBor.LK!MTB
ViRobotBackdoor.Win32.A.Rbot.110592.AI
ZoneAlarmTrojan.Win32.Eb.dgo
GDataWin32.Trojan.PSE1.C1KH17
VaristW32/Allaple.I.gen!Eldorado
AhnLab-V3Worm/Win32.Allaple.R34300
Acronissuspicious
McAfeeExploit-DcomRpc.c.gen
TACHYONTrojan/W32.Eb.108544
VBA32BScope.Trojan.MTA.01233
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0CKK23
RisingBackdoor.IRCbot!8.B47 (TFE:2:CfLXO7FBrXI)
YandexTrojan.GenAsa!SsYPZlVWtgw
IkarusBackdoor.Win32.Allaple
FortinetW32/Allaple.NAC!worm
BitDefenderThetaAI:Packer.59F6A7B91E
AVGWin32:Allaple-D [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove BScope.Trojan.MTA.01233?

BScope.Trojan.MTA.01233 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment