Ransom Trojan

BScope.TrojanRansom.PolyRansom removal tips

Malware Removal

The BScope.TrojanRansom.PolyRansom is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.TrojanRansom.PolyRansom virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine BScope.TrojanRansom.PolyRansom?


File Info:

name: 22A6334B1B409586D7A6.mlw
path: /opt/CAPEv2/storage/binaries/8cf4b9273116d72273b1dc16f5aeed629414aa2b9c42a8ffe2d16df1fc5cc2d1
crc32: A39318D1
md5: 22a6334b1b409586d7a693d7b2e46e95
sha1: b8edb0f9a0ebd78f598f97675a0b794a2b67ee6f
sha256: 8cf4b9273116d72273b1dc16f5aeed629414aa2b9c42a8ffe2d16df1fc5cc2d1
sha512: dbd54da12a46bde43b488e6412fe438ea988a1c92423dbe53d8a777b9bc75ed9e4236d112306fdfb78ad87399c097f1278b315b5b0deae125c1b52ac3c2d1cb5
ssdeep: 12288:Q/vgu5ZxkFZvGyFWsHG1gL+GhYf3nQZGUqEPAnibUajCtF3:K1ZkPOyF0gLgPQZVAnibUak
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E8055AD688DEC551BFC9E4BFDDEC398510087F6A0365B8EB21B591242A000F66E75B2F
sha3_384: 4c26b7bd004f12477003049a358b01cd281b99a6143ed85cf058bb5af57e0c5cae77f12fdb91d711e20e04bb16ec7b72
ep_bytes: 83ec28e818ee0c00e901000000c3e80d
timestamp: 2015-02-07 09:53:36

Version Info:

0: [No Data]

BScope.TrojanRansom.PolyRansom also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.22a6334b1b409586
McAfeeW32/VirRansom.b!22A6334B1B40
CylanceUnsafe
ZillyaVirus.Virlock.Win32.2
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040fa5c1 )
K7GWTrojan ( 0040fa5c1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Virus.Virlock.e
SymantecW32.Virlock!gen1
ESET-NOD32a variant of Win32/Virlock.J
APEXMalicious
ClamAVWin.Virus.Virlock-6804475-0
KasperskyVirus.Win32.PolyRansom.f
BitDefenderWin32.Virlock.Gen.3
NANO-AntivirusVirus.Win32.Virlock.dsdros
MicroWorld-eScanWin32.Virlock.Gen.3
AvastWin32:Nabucur-C [Trj]
TencentVirus.Win32.Polyransom.f
Ad-AwareWin32.Virlock.Gen.3
EmsisoftWin32.Virlock.Gen.3 (B)
ComodoVirus.Win32.VirLock.GA@7lv9go
DrWebWin32.VirLock.16
VIPREVirus.Win32.Nabucur.c (v)
TrendMicroPE_VIRLOCK.A
McAfee-GW-EditionBehavesLike.Win32.VirRansom.cc
SophosML/PE-A + W32/VirRnsm-E
IkarusVirus.Win32.Virlock
GDataWin32.Virlock.Gen.3
JiangminWin32/Polyransom.f
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLVirus/Win32.PolyRansom.f
ArcabitWin32.Virlock.Gen.3
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
TACHYONVirus/W32.VirRansom.D
AhnLab-V3Win32/Nabucur.D.X1506
Acronissuspicious
BitDefenderThetaAI:FileInfector.AE99F02013
ALYacWin32.Virlock.Gen.3
MAXmalware (ai score=85)
VBA32BScope.TrojanRansom.PolyRansom
MalwarebytesMalware.AI.3939173794
TrendMicro-HouseCallPE_VIRLOCK.A
RisingMalware.Heuristic!ET#99% (RDMK:cmRtazqvh3nSVEPH6xrKBks1EaFC)
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.PolyRansom.b
FortinetW32/Virlock.B
AVGWin32:Nabucur-C [Trj]
Cybereasonmalicious.b1b409
PandaGeneric Suspicious

How to remove BScope.TrojanRansom.PolyRansom?

BScope.TrojanRansom.PolyRansom removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment