Trojan

About “BScope.TrojanClicker.VB” infection

Malware Removal

The BScope.TrojanClicker.VB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.TrojanClicker.VB virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering

How to determine BScope.TrojanClicker.VB?


File Info:

name: 9721F7F2F5751621E762.mlw
path: /opt/CAPEv2/storage/binaries/94ee939bf3852ca8e6872278e2260895bcf98c8f34e53277cacf123de0378459
crc32: 7B19221F
md5: 9721f7f2f5751621e76240b76b1d8bf7
sha1: c31ce305cf81c924d0301c1dc981131e820daeab
sha256: 94ee939bf3852ca8e6872278e2260895bcf98c8f34e53277cacf123de0378459
sha512: c77da08b72538901a6ffea3b9527750e1822c3fc49edee52f3cf78a38206799f432b7e3a0110a64cd3141bd8fc0edaded398469cb4be89ebecd73e67bf84c44d
ssdeep: 6144:0KAWyjWg0hMscybtVP0RqzjlY5DcumpGfPjcg+3mnugiZ0BNOr+PDGhwgbIN3:0+IGfcybtRqiZpGfPwg+WcEOSFgE3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T115F4AE32B6E390B6C65A1430097B6735EA75EA4A0B11CFC35354DE2C9F325A1ED3723A
sha3_384: e5b28f78c7561e53dc636af3caa04a3c8f62895254dcb10f110fe5aae8204ace9af9e57eed4073e191aaafef5c89eca5
ep_bytes: 558bec6aff68a0f848006844c5450064
timestamp: 2012-03-25 15:54:47

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 零点脚本专用浏览器
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

BScope.TrojanClicker.VB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lwSp
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.68841037
FireEyeGeneric.mg.9721f7f2f5751621
McAfeeArtemis!9721F7F2F575
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Agent.Vcsn
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_60% (W)
CyrenW32/S-47c1ea66!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
BitDefenderTrojan.GenericKD.68841037
AvastWin32:TrojanX-gen [Trj]
EmsisoftTrojan.GenericKD.68841037 (B)
F-SecureTrojan:W32/DelfInject.R
VIPRETrojan.GenericKD.68841037
McAfee-GW-EditionBehavesLike.Win32.Generic.bh
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Application.PSE.1THOGOA
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumWorm.Win32.Dropper.RA@1qraug
ArcabitTrojan.Generic.D41A6E4D
MicrosoftProgram:Win32/Wacapew.C!ml
GoogleDetected
VBA32BScope.TrojanClicker.VB
ALYacTrojan.GenericKD.68841037
Cylanceunsafe
RisingTrojan.Generic@AI.93 (RDML:YHpSrO9ddrNVgm0g2WM2VA)
IkarusTrojan-Dropper.Age
MaxSecureDropper.Dinwod.frindll
FortinetRiskware/Application
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.5cf81c
DeepInstinctMALICIOUS

How to remove BScope.TrojanClicker.VB?

BScope.TrojanClicker.VB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment