Trojan

What is “BScope.Trojan.Sisproc”?

Malware Removal

The BScope.Trojan.Sisproc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Trojan.Sisproc virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine BScope.Trojan.Sisproc?


File Info:

name: 899C4976EA4B347196F6.mlw
path: /opt/CAPEv2/storage/binaries/8e41570808fe6e1bbd028cf47f8ca5566d9050857491bc5da520178fb1ed0b8d
crc32: 9E48CA95
md5: 899c4976ea4b347196f6b6b9fb13cb6e
sha1: 9f0db2997ae272a4596c498e2bda14bb2c06bb09
sha256: 8e41570808fe6e1bbd028cf47f8ca5566d9050857491bc5da520178fb1ed0b8d
sha512: 503ddb33b1d02c815fa79ea5c16e838151589297f737274597516a500c060785919aca8a5161b2f7d97f00e7931cb1062cc3e038cda9fbea6a9f4a95289b23f7
ssdeep: 98304:oHWRO3a1/EVaQFAyDxas/wjCsJKIk6qXS0Z3ibqyIGhB+mb0etzEv5OhD9oOdsai:o2RMHZFFDQj5JKIGi0ZSbq8eaVhEhO9+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EC3633FCA14D0424CE3ED33801D4A83C6C9BC685491B53AF159D653F1E622EE762B9AF
sha3_384: 3d10dcff13fba15661088fcfbf5be8791af215801294b6389383117c564d9166cb928416a222537a2021e3973d0a5e13
ep_bytes: 60be008044008dbe0090fbffc7870c97
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

BScope.Trojan.Sisproc also known as:

McAfeeArtemis!899C4976EA4B
K7GWTrojan ( 0055916a1 )
K7AntiVirusTrojan ( 0055916a1 )
Paloaltogeneric.ml
TencentMalware.Win32.Gencirc.11b7f333
SophosMal/Generic-S
GridinsoftRansom.Win32.STOP.sa
VBA32BScope.Trojan.Sisproc
MalwarebytesMalware.Heuristic.1003
APEXMalicious

How to remove BScope.Trojan.Sisproc?

BScope.Trojan.Sisproc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment