Trojan

Should I remove “OScope.Trojan.MSIL.Bitrans.W”?

Malware Removal

The OScope.Trojan.MSIL.Bitrans.W is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What OScope.Trojan.MSIL.Bitrans.W virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine OScope.Trojan.MSIL.Bitrans.W?


File Info:

name: 7D7CC1C54995ACB2D58D.mlw
path: /opt/CAPEv2/storage/binaries/7b65abc8f368961c4667c59072f5e35501aa3b8c5287246641d1b92a144edec5
crc32: 7A574AAE
md5: 7d7cc1c54995acb2d58d6b79246979d5
sha1: 91f2765ecf17c81f7e10e9f2f8e569eff94715d9
sha256: 7b65abc8f368961c4667c59072f5e35501aa3b8c5287246641d1b92a144edec5
sha512: 373a3eb129dbe0f08030ff01a02e48d3b7994843fa1813303a366b9737ee948c65f7d84f729bcfbec0c989373289fea21a6d9d7653d7d75dcbf407454fe6f51d
ssdeep: 24576:OqJo1ENc7aOHSApEGMYJXAklrDW83IhhmEQzR:OqicAXHSWETYNVlfp3IP9Q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T188559F91A1908D8BE86F06F1AD6AD53021E7AD5CA4A4C10D5ADA7F1B75F3312209FF0F
sha3_384: cb993a185760bbdb9627a3c35f06f8a4facfb070f52b3f99394e4e4e43639b13222950f4f5783342b06087b5dd163b08
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-09-27 05:17:30

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: Microsoft Corporation
FileDescription: Subst Utility
FileVersion: 1.0.0.0
InternalName: ytXm.exe
LegalCopyright: Copyright © Microsoft Corporation. All rights reserved.
LegalTrademarks:
OriginalFilename: ytXm.exe
ProductName: Subst Utility
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

OScope.Trojan.MSIL.Bitrans.W also known as:

BkavW32.AIDetectNet.01
LionicTrojan.MSIL.SnakeLogger.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.62372535
FireEyeGeneric.mg.7d7cc1c54995acb2
ALYacTrojan.GenericKD.62372535
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3918959
SangforSpyware.Msil.Kryptik.V8ew
K7AntiVirusTrojan ( 00598be61 )
AlibabaTrojan:Win32/Kryptik.ali2000016
K7GWTrojan ( 00598be61 )
CyrenW32/MSIL_Kryptik.DMH.gen!Eldorado
SymantecScr.Malcode!gdn34
ESET-NOD32a variant of MSIL/Kryptik.AGOR
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.LokiBot-9971787-0
KasperskyHEUR:Trojan-Spy.MSIL.SnakeLogger.gen
BitDefenderTrojan.GenericKD.62372535
NANO-AntivirusTrojan.Win32.SnakeLogger.jtefbo
AvastWin32:CrypterX-gen [Trj]
TencentMsil.Trojan-Spy.Snakelogger.Ytjl
Ad-AwareTrojan.GenericKD.62372535
EmsisoftTrojan.GenericKD.62372535 (B)
ComodoMalware@#1gr33uxsj545z
DrWebTrojan.PackedNET.389
VIPRETrojan.GenericKD.62372535
TrendMicroTROJ_GEN.R03BC0DIU22
McAfee-GW-EditionGenericRXUJ-BF!7D7CC1C54995
SophosMal/Generic-S + Troj/Krypt-RD
IkarusTrojan-Spy.Azorult
GDataTrojan.GenericKD.62372535
GoogleDetected
AviraTR/Dropper.MSIL.ujfwd
Antiy-AVLTrojan/Generic.ASMalwS.3E3F
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D3B7BAB7
ZoneAlarmHEUR:Trojan-Spy.MSIL.SnakeLogger.gen
MicrosoftTrojan:Win32/Leonem
CynetMalicious (score: 99)
AhnLab-V3Malware/Win.Generic.C5245891
McAfeeGenericRXUJ-BF!7D7CC1C54995
MAXmalware (ai score=100)
VBA32OScope.Trojan.MSIL.Bitrans.gen.W
MalwarebytesTrojan.MalPack.PNG.Generic
TrendMicro-HouseCallTROJ_GEN.R03BC0DIU22
RisingSpyware.SnakeLogger!8.15FDD (CLOUD)
YandexTrojan.Igent.bYNfRC.7
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.AGQB!tr
BitDefenderThetaGen:NN.ZemsilF.34754.tn0@aS7@esd
AVGWin32:CrypterX-gen [Trj]
PandaTrj/Chgt.AD

How to remove OScope.Trojan.MSIL.Bitrans.W?

OScope.Trojan.MSIL.Bitrans.W removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment