Trojan

What is “BScope.Trojan.Wacatac”?

Malware Removal

The BScope.Trojan.Wacatac is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What BScope.Trojan.Wacatac virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine BScope.Trojan.Wacatac?


File Info:

crc32: 1DDCC4F8
md5: dc2a5b9b07eb864629b82e912ac6737d
name: starticon5.exe
sha1: 9227291ec8c99d8ef524359dfd1da2c026945b61
sha256: f39c954c592021cf567b3bec1793399e80df0cfbf89816772f851c761c2387fb
sha512: d1373f1ce94b26867cdf23f4e1540ae5dd97c75ece7f4bfe5626e00eca4936a0b9fafcf26b58b267f8201aff7a47bc8bb6064d67be8c9dbcce871fd902449210
ssdeep: 12288:iN7qngfWyubuNNq9AQgLK1XiQVngIWvxFkacSpMsPRmbSm+j6RAvJcmaUtva:i9qYWyoA0yGngIWvxSajrRmbSoRiDRa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2019, ghjhfkh
InternalName: fyukfuyk.exe
FileVersion: 1.0.5.4
Translation: 0x0841 0x04c4

BScope.Trojan.Wacatac also known as:

MicroWorld-eScanTrojan.GenericKD.32652689
CAT-QuickHealRansom.STOP.S8831455
McAfeeRDN/Generic.grp
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Zbot.m6l9
K7AntiVirusTrojan ( 0055a7311 )
AlibabaTrojan:Win32/Injector.8763b290
K7GWTrojan ( 0055a7311 )
Cybereasonmalicious.ec8c99
ArcabitTrojan.Generic.D1F23D91
TrendMicroTROJ_FRS.VSNW1DJ19
F-ProtW32/Kryptik.API.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Injector.EION
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-7366725-0
KasperskyHEUR:Trojan.Win32.Chapak.pef
BitDefenderTrojan.GenericKD.32652689
NANO-AntivirusTrojan.Win32.Dwn.gffugx
RisingTrojan.Generic@ML.97 (RDMK:JcMuME0NbqVQHDb6HXxr4w)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.32652689 (B)
F-SecureTrojan.TR/AD.InstaBot.bxbli
DrWebTrojan.DownLoader30.31303
ZillyaTrojan.Injector.Win32.663188
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
FortinetW32/Injector.EION!tr
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.dc2a5b9b07eb8646
SophosMal/GandCrab-G
SentinelOneDFI – Malicious PE
CyrenW32/Trojan.UDHO-2675
WebrootW32.Malware.Gen
AviraTR/AD.InstaBot.bxbli
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.GandCrab
MicrosoftTrojan:Win32/Predator.PA!MTB
ZoneAlarmHEUR:Trojan.Win32.Chapak.pef
AhnLab-V3Trojan/Win32.RL_MalPe.R296523
Acronissuspicious
VBA32BScope.Trojan.Wacatac
ALYacTrojan.Ransom.Stop
Ad-AwareTrojan.GenericKD.32652689
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_FRS.VSNW1DJ19
YandexTrojan.Injector!rX0vKFAxuuk
IkarusTrojan.Inject
GDataTrojan.GenericKD.32652689
BitDefenderThetaGen:NN.ZexaF.32248.SG0@a8XRp5o
AVGWin32:CrypterX-gen [Trj]
AvastWin32:CrypterX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Trojan.Generic

How to remove BScope.Trojan.Wacatac?

BScope.Trojan.Wacatac removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment