Trojan

What is “BScope.Trojan.Orsam”?

Malware Removal

The BScope.Trojan.Orsam is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Trojan.Orsam virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine BScope.Trojan.Orsam?


File Info:

crc32: 1F1A72C0
md5: db1c0301fa05829eb6de51659d160199
name: text_editor.exe
sha1: f51ff685c416c735767049b3143921691005fd3f
sha256: 4a64c4b8983a5b9c982af89ce30a877a5279a4a2ce003d548929a167951f04be
sha512: 957cb91cab84b401c0b4c1c8cd976c505ea424cba96418cde3a60e390bb8609084f55cd37d50cec2c0be1762211429bfb5a54a6ab6719a9c371bcaaeb350aca5
ssdeep: 12288:tD6gKDevDg+2IRhUYOvGCqs21riqi2NVn47U7+R5nWFpPoStnLo6ui:tfKDevDg+TR2JvJqsMrpiIV4Qhbfnx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x5e97x5c0fx961f x7248x6743x6240x6709
FileVersion: 1.0.0.0
CompanyName: x5e97x5c0fx961f
Comments: x5e97x5c0fx961fx8fc7x6ee4x8bcdx5728x7ebfx67e5x8be2x7cfbx7edf
ProductName: x5e97x5c0fx961fx8fc7x6ee4x8bcdx5728x7ebfx67e5x770bx7cfbx7edf
ProductVersion: 1.0.0.0
FileDescription: x5e97x5c0fx961fx8fc7x6ee4x8bcdx5728x7ebfx67e5x8be2x7cfbx7edf
Translation: 0x0804 0x04b0

BScope.Trojan.Orsam also known as:

K7AntiVirusTrojan ( 005246d51 )
CAT-QuickHealTrojan.IGENERIC
McAfeeRDN/Generic.dx
CylanceUnsafe
K7GWTrojan ( 00013a151 )
CrowdStrikemalicious_confidence_90% (W)
Invinceaheuristic
F-ProtW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0PJR18
Paloaltogeneric.ml
ClamAVWin.Malware.Zusy-6840460-0
GDataWin32.Trojan.Agent.JVNFTY
ViRobotAdware.Packed.929792
ComodoWorm.Win32.Dropper.RA@1qraug
TrendMicroTROJ_GEN.R002C0PJR18
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SophosMal/Generic-S
CyrenW32/Agent.EW.gen!Eldorado
MAXmalware (ai score=100)
Antiy-AVLGrayWare/Win32.FlyStudio.a
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Malware/Win32.Generic.C2824955
Acronissuspicious
VBA32BScope.Trojan.Orsam
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
SentinelOnestatic engine – malicious
FortinetW32/Generic_PUA_PF
AVGWin32:Malware-gen
Cybereasonmalicious.5c416c
AvastWin32:Malware-gen

How to remove BScope.Trojan.Orsam?

BScope.Trojan.Orsam removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment