Trojan

BScope.TrojanDownloader.Alien removal instruction

Malware Removal

The BScope.TrojanDownloader.Alien is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.TrojanDownloader.Alien virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Attempts to execute a powershell command with suspicious parameter/s
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
paste.ee
a.tomx.xyz

How to determine BScope.TrojanDownloader.Alien?


File Info:

crc32: CC7D1528
md5: a3dc7df15140713154fe401d447b8226
name: decoder.exe
sha1: cc9f46a6fbe786ab56d4399d73a475ff89880ffa
sha256: 4caa96f3601e47b41c73951e22e3c42aa012a64e83eafcd164ddf1363a9b4c80
sha512: 89e6eeedaac25ffc3dd5077792c5b4f86f2065778bb37c91116521bda29f44b2208f206b002133966b25bb7fccafad2682e800b56b99caf14ec91258875001dc
ssdeep: 384:56NolEd7DvYgY8qNXUd+vgvD54gM5oazHXd+Uv:Gd70vgr54gGj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

BScope.TrojanDownloader.Alien also known as:

CylanceUnsafe
SangforMalware
BitDefenderThetaGen:NN.ZexaF.34090.bWY@aKHDv7d
APEXMalicious
RisingMalware.Heuristic!ET#79% (RDMK:cmRtazq84+MRqxESqKipdWJmeSr6)
VBA32BScope.TrojanDownloader.Alien
CrowdStrikewin/malicious_confidence_60% (W)

How to remove BScope.TrojanDownloader.Alien?

BScope.TrojanDownloader.Alien removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment