Trojan

About “BScope.Trojan.Python” infection

Malware Removal

The BScope.Trojan.Python is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Trojan.Python virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine BScope.Trojan.Python?


File Info:

name: F9D2ADBE7F0265D92216.mlw
path: /opt/CAPEv2/storage/binaries/340faac801cfd69d805536c67108b4615a72948789ba674fbe7feb050b479f9f
crc32: D20AEEDF
md5: f9d2adbe7f0265d9221601724fe0d35b
sha1: 6950ac1bc25afc29e702cf989589373875ecc6d0
sha256: 340faac801cfd69d805536c67108b4615a72948789ba674fbe7feb050b479f9f
sha512: e77dbb69c3865b295ee1f3a9e6ab743d1a8d09f9d4d94b573ae7d09d549f34c35efea43efb3f43a0a30fa4856661c84ffcf89acf9305cce3e3880c3bf7021a87
ssdeep: 98304:lT5cPzHgsAQAnGvVm/ixFIHIHfGsMTrNVgoatN6gZk+PUV:Hoq9zHIHnY3JsN9kZV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CA063388A2E59FEFF2BB443340A86A3454F95E0F0544107F5ADE3D0C9B67241DB68AF5
sha3_384: 98879c18ef6bc41f92c834dd617a36df7f583b1599dcef417927216c72c3becdac4f5f5fbb410ee3846286f04728c8a1
ep_bytes: 60be000046008dbe0010faff5783cdff
timestamp: 2021-06-11 09:16:54

Version Info:

0: [No Data]

BScope.Trojan.Python also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Uztuby.9
BitDefenderTrojan.Uztuby.9
Cybereasonmalicious.e7f026
APEXMalicious
SophosGeneric ML PUA (PUA)
F-SecureHeuristic.HEUR/AGEN.1122960
McAfee-GW-EditionBehavesLike.Win32.Backdoor.wc
FireEyeGeneric.mg.f9d2adbe7f0265d9
EmsisoftTrojan.Uztuby.9 (B)
GDataTrojan.GenericKDZ.78844
AviraHEUR/AGEN.1122960
ArcabitTrojan.Uztuby.9
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
AhnLab-V3Malware/Win.Generic.R439038
VBA32BScope.Trojan.Python
ALYacTrojan.GenericKDZ.78844
MAXmalware (ai score=89)
SentinelOneStatic AI – Malicious PE

How to remove BScope.Trojan.Python?

BScope.Trojan.Python removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment