Trojan

BScope.Trojan.Razy information

Malware Removal

The BScope.Trojan.Razy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Trojan.Razy virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 127.0.0.1:14656
  • Unconventionial language used in binary resources: Turkish
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Collects information to fingerprint the system

How to determine BScope.Trojan.Razy?


File Info:

crc32: EFAE9373
md5: 78f15ce91f8ab7161c1d254b22675f0a
name: 78F15CE91F8AB7161C1D254B22675F0A.mlw
sha1: ec253238121a06b0b681f608ba641aaf3af67e2d
sha256: 01fa7d1897bf020d72ed5948b55a466e142f6b8cf61ea00343db33f131735f0b
sha512: 51d8f24ce9984b28a38e5beade17d6acc00bbb25c0aa6c3495e3b1be588a57f2dedd3e7efc61600a7f5952c3b889bbff0e26c3bb4c43917857a1f84d37a69e45
ssdeep: 98304:fGkZG0V29rCF5wcFlMtH7doovl9Sx9pjcDSLxTOoA7Sp3i4fMdrkIvVfJAS7x/3:PZGP9mFStHrd9C9pj36FSlfgNfJAet3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersus: 1.9.37.29
FileVerus: 1.0.52.18
Translations: 0x0286 0x01ea

BScope.Trojan.Razy also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
Cybereasonmalicious.8121a0
CyrenW32/Kryptik.DZC.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
SophosML/PE-A + Mal/GandCrypt-A
BitDefenderThetaGen:NN.ZexaF.34686.@BW@aeBJJLgO
McAfee-GW-EditionBehavesLike.Win32.Lockbit.tc
FireEyeGeneric.mg.78f15ce91f8ab716
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen3
MicrosoftTrojan:Win32/Wacatac.B!ml
VBA32BScope.Trojan.Razy
MalwarebytesMalware.AI.3272593802
RisingMalware.Heuristic!ET#91% (RDMK:cmRtazofzeIsK1DsbnpY4xaW/PEX)
IkarusTrojan-Spy.Agent

How to remove BScope.Trojan.Razy?

BScope.Trojan.Razy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment