Spy Trojan

How to remove “BScope.TrojanSpy.Zbot”?

Malware Removal

The BScope.TrojanSpy.Zbot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.TrojanSpy.Zbot virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Creates a copy of itself

How to determine BScope.TrojanSpy.Zbot?


File Info:

crc32: 1BFD8D7C
md5: 85685b961e3bae2dc7e09b916871ed26
name: vvvv.exe
sha1: 3cf2100f3bd5a89fb7056d713a2328b213b252e5
sha256: acc9f555eecc9591ebc636a98d8cd5ea8e4f49ddd09b308a72a420e34af8a37f
sha512: 28d7ac513881d85a85526afa9ef18269f71088684c2a6e19bc515a6940da8ce69437083ace4836cfd8addba32586146433fea0f63fea980bc866221efcfb5a48
ssdeep: 24576:yNI8eYUVK/faOVEAHGTMkr5ujVazCbgUrd9mHZ0j51ucJBLRRF4mZJJQQ9slp9P:y5Hfzng5sVazixj5YEF4iJRs7x
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: LaKala (c). All rights reserved.
InternalName: But Leaveform
CompanyName: LaKala
LegalTrademarks: LaKala (c). All rights reserved.
Comments: Standoff Iscmpleted Understad Clone Charges Rather
ProductName: But Leaveform
ProductVersion: 5.6.5.9
FileDescription: Standoff Iscmpleted Understad Clone Charges Rather
Translation: 0x0409 0x04b0

BScope.TrojanSpy.Zbot also known as:

MicroWorld-eScanTrojan.GenericKD.33566228
McAfeeArtemis!85685B961E3B
CylanceUnsafe
BitDefenderTrojan.GenericKD.33566228
TrendMicroPossible_HPGen-38
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataWin32.Trojan.Agent.2FGKHP
KasperskyTrojan-Dropper.Win32.Dropback.ln
AegisLabTrojan.Multi.Generic.4!c
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.33566228 (B)
DrWebTrojan.Inject3.36700
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
IkarusTrojan-Ransom.GandCrab
AviraTR/AD.Carberp.zvmfv
eGambitUnsafe.AI_Score_98%
MicrosoftTrojan:Win32/Wacatac.C!ml
ZoneAlarmTrojan-Dropper.Win32.Dropback.ln
BitDefenderThetaGen:NN.ZexaF.34104.Uv0@aaC8!rii
VBA32BScope.TrojanSpy.Zbot
ESET-NOD32a variant of Generik.EXVGCZP
TrendMicro-HouseCallPossible_HPGen-38
FortinetW32/Generik.EXVGCZP!tr
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360HEUR/QVM10.1.23B9.Malware.Gen

How to remove BScope.TrojanSpy.Zbot?

BScope.TrojanSpy.Zbot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment