Trojan

How to remove “BScope.Trojan.Scarsi”?

Malware Removal

The BScope.Trojan.Scarsi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Trojan.Scarsi virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Harvests information related to installed mail clients

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine BScope.Trojan.Scarsi?


File Info:

crc32: 47803248
md5: ed78e69ca0ace8eccdf14621057b03e2
name: wire0212_dec_keylog_5cr68.exe
sha1: 711b70bba426b9570b777fd4b27cc1d5600866c9
sha256: ad69987e65b754f9adb9b55787e5572a0f68f427f4ec513cdc72114f9151ed3c
sha512: 9f0421f4e77ad68e25baa2bec56f5c9a10c3c78e9205c76e5ff6ec118e4b17b64210932c51f5f76a831d65efd6a9e069d9a1a129004f52e3beb2667029988fab
ssdeep: 24576:MkRPNHMMja9dBcjFEj+nJYZCakOXbeWv9rU4D0:tNsMjafBuJKCakOqWvu4D
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: All rights reserved.
InternalName: LengthEnvision
FileVersion: 7.5.2.5
CompanyName: Emurasoft, Inc.
LegalTrademarks: All rights reserved.
Comments: Fun Latino Htfix Rice
ProductName: LengthEnvision
Languages: English
ProductVersion: 7.5.2.5
FileDescription: Fun Latino Htfix Rice
Translation: 0x0409 0x04b0

BScope.Trojan.Scarsi also known as:

MicroWorld-eScanTrojan.GenericKD.32780839
BitDefenderThetaGen:NN.ZexaF.32519.WmKfayUjVBii
ALYacTrojan.GenericKD.32780839
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.32780839
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.ba426b
Invinceaheuristic
CyrenW32/Trojan.WXBY-1511
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataWin32.Trojan-Stealer.AgentTesla.HVM87K
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/Kryptik.df7ddd50
AegisLabTrojan.Multi.Generic.4!c
Endgamemalicious (moderate confidence)
EmsisoftTrojan.GenericKD.32780839 (B)
ComodoMalware@#usv4s6iixske
DrWebTrojan.PWS.Siggen2.39988
ZillyaTrojan.Kryptik.Win32.1870995
McAfee-GW-EditionBehavesLike.Win32.PUPXCK.bc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
ArcabitTrojan.Generic.D1F43227
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Tiggre!rfn
Acronissuspicious
McAfeeRDN/Generic.dx
MAXmalware (ai score=87)
VBA32BScope.Trojan.Scarsi
MalwarebytesSpyware.AgentTesla
ESET-NOD32a variant of Win32/Kryptik.GZBP
TrendMicro-HouseCallTROJ_GEN.R053H0CL619
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.GVSM!tr
Ad-AwareTrojan.GenericKD.32780839
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/QVM11.1.BAB3.Malware.Gen

How to remove BScope.Trojan.Scarsi?

BScope.Trojan.Scarsi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment