Trojan

How to remove “BScope.TrojanDownloader.Ajent”?

Malware Removal

The BScope.TrojanDownloader.Ajent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.TrojanDownloader.Ajent virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Georgian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine BScope.TrojanDownloader.Ajent?


File Info:

name: 156981359BF3FF0CDCC0.mlw
path: /opt/CAPEv2/storage/binaries/682a771521e2e8454a606714774e73f8c24f3023348eda7a7e2d9f60901f068e
crc32: 2B565C26
md5: 156981359bf3ff0cdcc04c0638041770
sha1: d20db22277ecb7d2bb664d6483a728a689b14db2
sha256: 682a771521e2e8454a606714774e73f8c24f3023348eda7a7e2d9f60901f068e
sha512: 3840d57573d1c526b0abf62678a6dda7b17e6a94ab609ac10d0797b7899706447447f7c12cae8029cf18b45e5d9e29c68421567b16fb6b4a8a63139bc1dacfd8
ssdeep: 24576:LoEH/nw7NUZQ/Ws5uV9m3iNR/F1+yLXCEQ11ou1D1EtCsQhkAzjItSnUte1WTnPw:LoyffZQ/L58M3ipdw11oqZEtEz0tSUtK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15F652329B6B2D4F1C6E232704825CBE46BBF7836D674859B36A4175A3E732C04A7035F
sha3_384: 0ba8d8b56b94e387d58802b2b1c0a2bd4b58e3ea72ceb5c93c33a7f469b0048e9a09841e5d0456336f13470376361ccb
ep_bytes: e817650000e978feffffcccccccccccc
timestamp: 2021-05-07 04:01:43

Version Info:

FileVersions: 12.30.9.87
InternationalName: povgwaoci.iwe
Copyright: Copyright (C) 2022, somoklos
ProjectVersion: 82.42.46.96

BScope.TrojanDownloader.Ajent also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Zard.52
FireEyeGeneric.mg.156981359bf3ff0c
CAT-QuickHealRansom.Stop.P5
ALYacGen:Heur.Mint.Zard.52
CylanceUnsafe
SangforTrojan.Win32.Save.a
BitDefenderGen:Heur.Mint.Zard.52
Cybereasonmalicious.277ecb
CyrenW32/Ransom.QS.gen!Eldorado
SymantecPacked.Generic.525
tehtrisGeneric.Malware
APEXMalicious
ClamAVWin.Packed.Tofsee-9951336-0
KasperskyUDS:DangerousObject.Multi.Generic
RisingTrojan.Generic@AI.100 (RDML:b+e012q5pt8mbZ1914OPSg)
Ad-AwareGen:Heur.Mint.Zard.52
EmsisoftGen:Heur.Mint.Zard.52 (B)
VIPREGen:Heur.Mint.Zard.52
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.moderate.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GoogleDetected
MAXmalware (ai score=81)
MicrosoftRansom:Win32/StopCrypt.SL!MTB
GDataGen:Heur.Mint.Zard.52
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.TrojanDownloader.Ajent
MalwarebytesTrojan.MalPack.GS
IkarusTrojan.Win32.Crypt
AVGPWSX-gen [Trj]
AvastPWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove BScope.TrojanDownloader.Ajent?

BScope.TrojanDownloader.Ajent removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment