Spy Trojan

BScope.TrojanSpy.Xegumumune (file analysis)

Malware Removal

The BScope.TrojanSpy.Xegumumune is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.TrojanSpy.Xegumumune virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine BScope.TrojanSpy.Xegumumune?


File Info:

name: 11DFC72BF09F73738F4E.mlw
path: /opt/CAPEv2/storage/binaries/3f7a7115a10dd40c2c2228adebbd3b3c53159c033c83a9b86eadb80b00005f84
crc32: 46366996
md5: 11dfc72bf09f73738f4e043802b2e768
sha1: debc356a7e91d21974b5e5f038fbfd11b7780dfa
sha256: 3f7a7115a10dd40c2c2228adebbd3b3c53159c033c83a9b86eadb80b00005f84
sha512: 88016777c540bf75d7283f62068ca0d867ae7b79d6965a7c224dfb30337fb6badd40e87278f9daef0d9a829f13eb4cb20f0f48675978afb77aa0e7e9082e8793
ssdeep: 3072:belH3lLNa7RH8enY+lB1P4V1hkx+IIsxdDT:y3GT1gVfkvxxT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T176D30A4CEE5758F5EE1729F05496FBFFC2209E25D834CE35EA18C751F932AD20A0A189
sha3_384: 4fed8e2205e827bed6164426b590e0643019f0ff7d06b099998ba8b5243fc19b1e5bd7827aa4d9a9549e664e005ca37d
ep_bytes: 83ec0cc7053491420001000000e8ee6e
timestamp: 2021-11-21 15:28:20

Version Info:

0: [No Data]

BScope.TrojanSpy.Xegumumune also known as:

Elasticmalicious (high confidence)
FireEyeGen:Trojan.Heur.JP.hCW@aCgPjci
ALYacGen:Trojan.Heur.JP.hCW@aCgPjci
CylanceUnsafe
Cybereasonmalicious.bf09f7
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 99)
BitDefenderGen:Trojan.Heur.JP.hCW@aCgPjci
MicroWorld-eScanGen:Trojan.Heur.JP.hCW@aCgPjci
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Trojan.Heur.JP.hCW@aCgPjci
McAfee-GW-EditionBehavesLike.Win32.Trojan.ch
EmsisoftGen:Trojan.Heur.JP.hCW@aCgPjci (B)
GDataGen:Trojan.Heur.JP.hCW@aCgPjci
AviraHEUR/AGEN.1141962
ViRobotTrojan.Win32.Z.Win.130048
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Malware/Win.Reputation.R374766
McAfeeGenericRXQU-YT!11DFC72BF09F
MAXmalware (ai score=89)
VBA32BScope.TrojanSpy.Xegumumune
MalwarebytesMalware.AI.2742422003
TrendMicro-HouseCallTROJ_GEN.R002H09KL21
FortinetW32/PossibleThreat
BitDefenderThetaAI:Packer.82B08F271E
AVGWin32:TrojanX-gen [Trj]

How to remove BScope.TrojanSpy.Xegumumune?

BScope.TrojanSpy.Xegumumune removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment