Trojan

BScope.Trojan.VBCR.1912 removal tips

Malware Removal

The BScope.Trojan.VBCR.1912 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Trojan.VBCR.1912 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine BScope.Trojan.VBCR.1912?


File Info:

name: FCC2838BF4BF38D40589.mlw
path: /opt/CAPEv2/storage/binaries/3ee5acd6dc009a45fcab9b73a6dcd8bc2e7caf0282753d3c05078a792a1d1c22
crc32: EC528145
md5: fcc2838bf4bf38d405890ac2cd2002cd
sha1: 1c6e11e75af6a671322db6f54b1731b1a1ea7fa6
sha256: 3ee5acd6dc009a45fcab9b73a6dcd8bc2e7caf0282753d3c05078a792a1d1c22
sha512: 168c014254236a10409529226105bbd278f7c1ec4ab2df12605ee672aa8f696cd3a4d4b3931843a2748d2a1611fcc5f485c6f5340a70af3dae5469e8294303a0
ssdeep: 6144:n1BirvbGuOdn9Z/QmO6Ckobf3fGCmahGkUutZ:6rvbGuYnXQmO6Ckobf3fGCmah7Uq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17654A4297380FB2DD061C6F03A4A43A5947EAD7255E06807F7C17F2A72B2D9BE520727
sha3_384: 930e43a794c845ea86d343eea99e9b16a5901f0c259416ab78092a4796e85afaddacda6eed3f29f55abade4e8e8d802b
ep_bytes: 6878474000e8f0ffffff000000000000
timestamp: 2008-07-08 13:32:19

Version Info:

Translation: 0x0409 0x04b0
ProductName: aQTBLafXt
FileVersion: 1.00
ProductVersion: 1.00
InternalName: FjerJiqn
OriginalFilename: FjerJiqn.exe

BScope.Trojan.VBCR.1912 also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.low6
Elasticmalicious (high confidence)
DrWebTrojan.VbCrypt.60
MicroWorld-eScanGen:Variant.Chinky.7
FireEyeGeneric.mg.fcc2838bf4bf38d4
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.cm
Cylanceunsafe
ZillyaWorm.Vobfus.Win32.1523941
SangforSuspicious.Win32.Save.vb
AlibabaWorm:Win32/Vobfus.9f064717
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
BitDefenderThetaGen:NN.ZevbaF.36804.sm0@aSbkXSbi
Paloaltogeneric.ml
SymantecW32.Changeup!gen15
tehtrisGeneric.Malware
ESET-NOD32Win32/Pronny.AA
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMAB
AvastWin32:AutoRun-CMZ [Trj]
ClamAVWin.Trojan.Vobfus-70360
KasperskyWorm.Win32.Vobfus.dfpi
BitDefenderGen:Variant.Chinky.7
NANO-AntivirusTrojan.Win32.VB.cinaxx
SUPERAntiSpywareTrojan.Agent/Gen-Vban
TencentWorm.Win32.Vobfus.n
EmsisoftGen:Variant.Chinky.7 (B)
F-SecureTrojan.TR/Diple.eecq
BaiduWin32.Trojan.VBObfus.f
VIPREGen:Variant.Chinky.7
TrendMicroWORM_VOBFUS.SMAB
Trapminemalicious.high.ml.score
SophosW32/VB-FRK
IkarusWorm.Win32.Vobfus
GoogleDetected
AviraTR/Diple.eecq
VaristW32/Vobfus.Z.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
KingsoftWin32.Worm.Vobfus.dfpi
MicrosoftWorm:Win32/Vobfus!pz
XcitiumWorm.Win32.Pronny.AK@4p6cu6
ArcabitTrojan.Chinky.7
ZoneAlarmWorm.Win32.Vobfus.dfpi
GDataGen:Variant.Chinky.7
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Menti.R19092
Acronissuspicious
VBA32BScope.Trojan.VBCR.1912
ALYacGen:Variant.Chinky.7
TACHYONWorm/W32.Vobfus.294912.C
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.GEW.worm
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!3dGi5AJ9CaE
MAXmalware (ai score=85)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Diple.EJQE!tr
AVGWin32:AutoRun-CMZ [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Vobfus.46f1e700

How to remove BScope.Trojan.VBCR.1912?

BScope.Trojan.VBCR.1912 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment