Trojan

What is “BScope.Trojan.Zebrocy”?

Malware Removal

The BScope.Trojan.Zebrocy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Trojan.Zebrocy virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine BScope.Trojan.Zebrocy?


File Info:

crc32: 635AB767
md5: c88e5ef4b70b12cdf023865e61bd85b2
name: C88E5EF4B70B12CDF023865E61BD85B2.mlw
sha1: a7bf932c3d1d4c9028ce7d481c825b65501df973
sha256: 20e94159364a27153887fdb1c6387edeb1ecb51035a11693119391be51e747f0
sha512: f3fbd928172a05868cf74ec0cf09868ef25467ae3659023ff034eb8a1558f583e7939c472d691e341c768b38a53218d3e16afd725b65635dfd92ab5f18937c7e
ssdeep: 196608:tqNL8SEzhvWUKKi7EzPFJ5wULnSrAIBjrgneTN:tqJMWXgjFJ5wULqvGk
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) Copyright (C) WiSiYiLink & LanConvey
InternalName: remote printer assistant
FileVersion: 2.1.19.3
CompanyName: Copyright (C) WiSiYiLink & LanConvey
ProductName: x8fdcx7a0bx6253x5370x673ax5b89x88c5x52a9x624b
ProductVersion: 2.1.19.3
FileDescription: x7528x4e8ex5b89x88c5x8fdcx7a0bx6253x5370x673ax9a71x52a8xff08x7528x5b8cx53efx5220x9664xff09
OriginalFilename: remote-printer-assistant.exe
Translation: 0x0009 0x04b0

BScope.Trojan.Zebrocy also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader36.27636
ESET-NOD32a variant of Win32/Packed.AAuto.B suspicious
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Malware.Emtfyaeqhwkb-9863426-0
KasperskyVHO:Trojan.Win32.Convagent.gen
NANO-AntivirusTrojan.Win32.Wofith.huqcgb
McAfee-GW-EditionGenericRXPB-KB!A3A07BF83EEF
SentinelOneStatic AI – Suspicious PE
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeGenericRXPB-KB!A3A07BF83EEF
VBA32BScope.Trojan.Zebrocy
MalwarebytesMalware.AI.4266307914
RisingTrojan.Generic@ML.91 (RDMK:MAuhoAqwF6feOSBm/nJarg)
YandexTrojan.GenAsa!Nly9AoXnxJE
AVGWin32:Evo-gen [Susp]

How to remove BScope.Trojan.Zebrocy?

BScope.Trojan.Zebrocy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment