Trojan

BScope.TrojanPSW.Predator removal

Malware Removal

The BScope.TrojanPSW.Predator is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.TrojanPSW.Predator virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Looks up the external IP address
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

advertspace10.club
logstat17.club
api.ipify.org

How to determine BScope.TrojanPSW.Predator?


File Info:

crc32: 4D6EC366
md5: 4d0f80f6e5dbc18341156c5b9990857e
name: ztx777.exe
sha1: 09230e7c09718d7823ba5331f052f2c255675420
sha256: 4f54f8c814072721bfbbc58abbc8978abf44e7355405f891ab01971371553ebf
sha512: fc8415ecefdeb6545a4b4fbc0c39100eb463ee9f9124dbbc9b4f1f044efcbb526c3c5dedb58279e9cf77d7dde5cd5275a927c26baf38fbef12cb2b376a386589
ssdeep: 3072:wpTmWkYcUZoXqPu8gHpBUrgBZdtjEDWv1oIq++3QStZ3iKF5iNlcw0hXHqvTxNd:wp2UL28oUrgBZ/+01oYeFd5iNiwf
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: TechSmith Corporation Copyright (c)
InternalName: 92a702a99b35Occupies
FileVersion: 3.7.7.3
CompanyName: TechSmith Corporation
FileDescription: Arises Exec Or Overruns
LegalTrademarks: TechSmith Corporation Copyright (c)
Comments: Arises Exec Or Overruns
ProductName: 92a702a99b35Occupies
Languages: English
ProductVersion: 3.7.7.3
PrivateBuild: 3.7.7.3
OriginalFilename: 92a702a99b35Occupies
Translation: 0x0409 0x04b0

BScope.TrojanPSW.Predator also known as:

DrWebTrojan.MulDrop11.30025
MicroWorld-eScanTrojan.GenericKD.32769525
FireEyeGeneric.mg.4d0f80f6e5dbc183
McAfeeArtemis!4D0F80F6E5DB
ALYacTrojan.GenericKD.32769525
MalwarebytesTrojan.MalPack.RVRS
SangforMalware
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderTrojan.GenericKD.32769525
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZexaF.32517.nmKfauuLkmfi
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataTrojan.GenericKD.32769525
KasperskyUDS:DangerousObject.Multi.Generic
AegisLabTrojan.Multi.Generic.4!c
RisingTrojan.Generic@ML.86 (RDML:M0J4M/qy0sZRvSrzc0nJ6A)
Endgamemalicious (moderate confidence)
ComodoMalware@#1s7h3fgtaic33
F-SecureTrojan.TR/AD.Coroxy.lnuzg
McAfee-GW-EditionBehavesLike.Win32.BadFile.dc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan-Ransom.GandCrab
CyrenW32/Trojan.BSNB-3962
WebrootW32.Trojan.Gen
AviraTR/AD.Coroxy.lnuzg
ArcabitTrojan.Generic.D1F405F5
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Tiggre!rfn
Acronissuspicious
VBA32BScope.TrojanPSW.Predator
Ad-AwareTrojan.GenericKD.32769525
CylanceUnsafe
ESET-NOD32a variant of Win32/GenKryptik.DYXU
TrendMicro-HouseCallTROJ_GEN.R002H0CL219
FortinetW32/Kryptik.GVSM!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.14f

How to remove BScope.TrojanPSW.Predator?

BScope.TrojanPSW.Predator removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment