Trojan

What is “BScope.Trojan.Tremp”?

Malware Removal

The BScope.Trojan.Tremp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Trojan.Tremp virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Attempts to connect to a dead IP:Port (11 unique times)
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.tengfeidn.com
tengfeidn.com
cdn.qqb3.com
cdn.cuilet.com
apps.game.qq.com
cdn.sackow.com
sp0.baidu.com
ocsp.globalsign.com
8s46n4vw.sched.sma.tdnsv5.com
ocsp2.globalsign.com
gweish.com
ddjf8dkd.mmakd.ren
site.ip138.com
ip.cn
ocsp.digicert.com

How to determine BScope.Trojan.Tremp?


File Info:

crc32: 54821DC4
md5: 9a85cfcb8e3911543ab9ff75c95005ff
name: 9A85CFCB8E3911543AB9FF75C95005FF.mlw
sha1: 02980b8f0de75613f793693ae5aff59c097a59f0
sha256: 2a790c3cc476892be4d97e62472e045bcb77a12b51c484aa2d809aa72c631254
sha512: ccaf70021abfc225f6e4acab7dfe59417cb211bf5e710531ccf54e7a5630f5292e611995c20521d250bb518a8f0cea0edb97ade29dadb8d3df5f8c224d58878c
ssdeep: 24576:uC7xU9l/BKPT4ns3loxSWTGJ5qrEBq5xndAc7iNFSpTSzXYO07GP3A6WVacWENU:PxU38PT4nglTP5PBq5pdAc7iXKSkOTx
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright 1999-2004 Sicent.Ltd. x7248x6743x6240x6709
FileVersion: 2.9.3.21
CompanyName: Copyright 1999-2004 Sicent.Ltd.
Comments: x4e07x8c61x7f51x7ba12008x670dx52a1x7aef
ProductName: x4e07x8c61x7f51x7ba12008x670dx52a1x7aef
ProductVersion: 2.9.3.21
FileDescription: x4e07x8c61x7f51x7ba12008x670dx52a1x7aefx542fx52a8x7a0bx5e8f
Translation: 0x0804 0x04b0

BScope.Trojan.Tremp also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005246d51 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Blackv.42ee48e7
K7GWTrojan ( 00013a151 )
Cybereasonmalicious.f0de75
CyrenW32/OnlineGames.HI.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Noobyprotect-6622929-0
KasperskyHEUR:Packed.Win32.Blackv.gen
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
BitDefenderThetaGen:NN.ZexaF.34686.DnKfaCXzF6eb
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.9a85cfcb8e391154
SentinelOneStatic AI – Malicious PE
JiangminTrojan.VBKrypt.dpcn
eGambitUnsafe.AI_Score_100%
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Packed.Win32.Blackv.gen
GDataWin32.Trojan.PSE.1QVDXLB
Acronissuspicious
McAfeeArtemis!9A85CFCB8E39
VBA32BScope.Trojan.Tremp
MalwarebytesMalware.AI.2164980524
RisingMalware.Heuristic!ET#99% (RDMK:cmRtazqXTGRryFc3lIgq9uRrbI7V)
YandexTrojan.GenAsa!+s06rT7H+cc
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.65CA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove BScope.Trojan.Tremp?

BScope.Trojan.Tremp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment