Trojan

How to remove “BScope.Trojan.VB.Onechki”?

Malware Removal

The BScope.Trojan.VB.Onechki is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Trojan.VB.Onechki virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine BScope.Trojan.VB.Onechki?


File Info:

name: 48B5E5285902C1E0FB3C.mlw
path: /opt/CAPEv2/storage/binaries/b613592e5129e8515ff4d1fc9c74f285cfdef4606295f1ad058d6b9196c4b399
crc32: C75CE7CE
md5: 48b5e5285902c1e0fb3c138645cb951d
sha1: ac93633e1e58242faefcc2e3e980823375f98212
sha256: b613592e5129e8515ff4d1fc9c74f285cfdef4606295f1ad058d6b9196c4b399
sha512: 9742ef9247622a2de4b3bd917667bb2041c6c3b691c4434cca65f4ffa621fc102542c40dd7a772905b0214c57a68ded634f48e47bb8a8e4eea199c63a1f04ca0
ssdeep: 6144:tj+xPxlLGKitxJ66onJGr+qyVztumGS5Ni3hpgoMKMphaeVf2B71Ak:tsPjLGKitF6JGr+qyVztumGS5YqoyU7z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C4648125AB18607BE41A85F5287E936A280C5E7603D0EC13F380BB98B4752E7B5F175F
sha3_384: 1a4c9c19f32e61fa0007cd3134ae2321e07bf5db710822ee1324066be276cf0ab4b7a9eab2a90b29fc51c48bbe6a7eac
ep_bytes: 6808444000e8f0ffffff000000000000
timestamp: 2012-03-06 03:55:48

Version Info:

0: [No Data]

BScope.Trojan.VB.Onechki also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.VBKrypt.lIpk
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.95598
ClamAVWin.Trojan.Vobfus-69
FireEyeGeneric.mg.48b5e5285902c1e0
CAT-QuickHealTrojan.Beebone.D
McAfeeVBObfus.dg
MalwarebytesGeneric.Worm.AutoRun.DDS
VIPRETrojan.GenericKDZ.95598
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/VBKrypt.8b5e4537
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.85902c
BaiduWin32.Worm.Autorun.l
VirITTrojan.Win32.Zyx.IR
CyrenW32/Vobfus.AD.gen!Eldorado
SymantecW32.Changeup!gen35
ESET-NOD32a variant of Win32/AutoRun.VB.AST
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.VBKrypt.kygz
BitDefenderTrojan.GenericKDZ.95598
NANO-AntivirusTrojan.Win32.VBKrypt.chzvje
SUPERAntiSpywareTrojan.Agent/Gen-Pronny
AvastWin32:VB-ABOE [Trj]
TencentTrojan.Win32.VBKrypt.hl
TACHYONTrojan/W32.VBKrypt.327680
EmsisoftTrojan.GenericKDZ.95598 (B)
F-SecureTrojan.TR/VB.Agent.aboe
DrWebWorm.Siggen.10730
ZillyaTrojan.VBKrypt.Win32.793179
TrendMicroWORM_VOBFUS.SMJA
McAfee-GW-EditionBehavesLike.Win32.VBObfus.fm
SophosMal/SillyFDC-W
IkarusWorm.Win32.Vobfus
GDataTrojan.GenericKDZ.95598
AviraTR/VB.Agent.aboe
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Pronny.AK@4ogvoo
ArcabitTrojan.Generic.D1756E
ViRobotTrojan.Win32.A.VBKrypt.327680.BR
ZoneAlarmTrojan.Win32.VBKrypt.kygz
MicrosoftWorm:Win32/Vobfus.gen!S
GoogleDetected
AhnLab-V3Trojan/Win32.VBKrypt.R117672
BitDefenderThetaGen:NN.ZevbaF.36250.umW@aWVDk1fi
ALYacTrojan.GenericKDZ.95598
MAXmalware (ai score=89)
VBA32BScope.Trojan.VB.Onechki
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMJA
RisingTrojan.VBEx!1.99EE (CLASSIC)
YandexTrojan.GenAsa!HEePpHwgKbs
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-ABOE [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove BScope.Trojan.VB.Onechki?

BScope.Trojan.VB.Onechki removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment