Trojan

Should I remove “BScope.Trojan.RRAT”?

Malware Removal

The BScope.Trojan.RRAT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Trojan.RRAT virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine BScope.Trojan.RRAT?


File Info:

name: AF287A577A128AE206EC.mlw
path: /opt/CAPEv2/storage/binaries/c747d4989101dd9086773eff1fec1f989671bd4678d0f979883796216e8a45e6
crc32: 70F52FCD
md5: af287a577a128ae206ec58a113914dcf
sha1: 670441df922cf02ac55fb9cea3d110442d81376d
sha256: c747d4989101dd9086773eff1fec1f989671bd4678d0f979883796216e8a45e6
sha512: 72ac7faf500534a36bf7601dd062ff23029cda95c36a9c1e64545c5a70ef64e60f16bd9e27dfed0d2e451891692cc559e895d7ee0b24e08ce0e69acc48c4b6b8
ssdeep: 6144:SWAKwwPYDiczY09umHh7K5cUXEBwrYVHhAgY6Vch:VAbyYDxY09umH45cUXEBwUVHhAgY6V2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10C24C5256390E63EE111CAF83A59C3A4556EAC3216D2AC07FBC03F1A77F1D679221763
sha3_384: f6c6ef60cda2021b536d8cb11bca29cbbb2f706e8bd5d0f38b3a6ceadd052e226b2e9b946e1d1e99b60e54337f52225f
ep_bytes: 6828424000e8f0ffffff000000000000
timestamp: 2012-10-17 18:59:18

Version Info:

Translation: 0x0409 0x04b0
ProductName: Scotoma
FileVersion: 5.11
ProductVersion: 5.11
InternalName: duskingtide
OriginalFilename: duskingtide.exe

BScope.Trojan.RRAT also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lDPa
MicroWorld-eScanGen:Variant.Barys.950
ClamAVWin.Trojan.Vobfus-31
FireEyeGeneric.mg.af287a577a128ae2
CAT-QuickHealTrojan.Beebone.D
ALYacGen:Variant.Barys.950
MalwarebytesVBObfus.Worm.Spreader.DDS
ZillyaWorm.WBNAGen.Win32.3
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Vobfus.c8c3638a
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Barys.950
BitDefenderThetaGen:NN.ZevbaF.36318.nm1@aO7DGMfi
VirITTrojan.Win32.VB.COXP
CyrenW32/VB.HE.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/VBObfus.BT
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Vobfus.xmh
BitDefenderGen:Variant.Barys.950
NANO-AntivirusTrojan.Win32.WBNA.cihugn
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:VB-AETH [Trj]
TencentTrojan.Win32.Vobfus.haw
TACHYONWorm/W32.Agent.217144
SophosMal/SillyFDC-AC
BaiduWin32.Worm.Pronny.d
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner1.28139
VIPREGen:Variant.Barys.950
TrendMicroWORM_VOBFUS.SMIV
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dm
EmsisoftGen:Variant.Barys.950 (B)
SentinelOneStatic AI – Suspicious PE
JiangminWorm/WBNA.dgqs
WebrootTrojan.Win32.Diple
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.Pronny.EE@4qvpy8
MicrosoftWorm:Win32/Vobfus.KA
ViRobotTrojan.Win32.Vobfus.Gen.A
ZoneAlarmTrojan.Win32.Vobfus.xmh
GDataWin32.Trojan.PSE.1LPQ1ED
GoogleDetected
AhnLab-V3Worm/Win32.Vobfus.R42639
McAfeeGenDownloader.rv
MAXmalware (ai score=100)
VBA32BScope.Trojan.RRAT
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMIV
YandexTrojan.GenAsa!cfHiHQQEREU
IkarusTrojan.VB
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-AETH [Trj]
Cybereasonmalicious.77a128
DeepInstinctMALICIOUS

How to remove BScope.Trojan.RRAT?

BScope.Trojan.RRAT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment