Malware

What is “SScope.Malware-Cryptor.Bayrob”?

Malware Removal

The SScope.Malware-Cryptor.Bayrob is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What SScope.Malware-Cryptor.Bayrob virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Creates a copy of itself

How to determine SScope.Malware-Cryptor.Bayrob?


File Info:

name: A692ADDBA1DE1C12D03B.mlw
path: /opt/CAPEv2/storage/binaries/b435bc89f5ac7e0e36fff8ecb796bcb5807e9b05c8e2100278f658d72e63c182
crc32: 2F086F34
md5: a692addba1de1c12d03b50c16b456013
sha1: af7e4e6f1273468b2feba3bb328ae5c6e38a07a2
sha256: b435bc89f5ac7e0e36fff8ecb796bcb5807e9b05c8e2100278f658d72e63c182
sha512: 2cf9f381b3cd1629d63a1b6c1590846c495a68d844fde834584f0af73ce72a36a36c31513302e596305ecd3adbafe165ca78a7af7b9f0176a637dc010c07a7c3
ssdeep: 12288:AOcwjb4HpLQkls20hxgeGAAsiWmC8xMe4+0xTA9:JcOb4JLQklexgtAATWZoD4+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T192D49D11B543A1B3D83265B34169E23B2A35BD7A0F29CAE3D7C70E3559F36C09A33256
sha3_384: 6fd54436d371e4b470fbb0f78409d49981fd2d77640a41550cf7b87343137205083cfb883f31c1d434972d719ee58937
ep_bytes: e81b420100e9000000006a146858d248
timestamp: 2014-12-10 21:46:26

Version Info:

0: [No Data]

SScope.Malware-Cryptor.Bayrob also known as:

BkavW32.FamVT.BRTTc.Worm
Elasticmalicious (high confidence)
DrWebTrojan.Bayrob.57
MicroWorld-eScanGen:Variant.Barys.58165
FireEyeGeneric.mg.a692addba1de1c12
CAT-QuickHealTrojanSpy.Nivdort.DR3
McAfeeTrojan-FINB!A692ADDBA1DE
CylanceUnsafe
ZillyaTrojan.SwizzorGen.Win32.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004dc2a31 )
K7GWTrojan ( 004dc2a31 )
Cybereasonmalicious.ba1de1
BitDefenderThetaAI:Packer.63B81A021E
CyrenW32/Nivdort.L.gen!Eldorado
SymantecTrojan.Bayrob!gen8
ESET-NOD32a variant of Win32/Bayrob.CS
TrendMicro-HouseCallTROJ_BAYROB.SM7
ClamAVWin.Malware.Bayrob-9908843-0
KasperskyHEUR:Trojan.Win32.Bayrob.gen
BitDefenderGen:Variant.Barys.58165
NANO-AntivirusTrojan.Win32.Bayrob.echswy
AvastFileRepMalware
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareGen:Variant.Barys.58165
SophosML/PE-A + Mal/Bayrob-C
BaiduWin32.Trojan.Bayrob.a
VIPRETrojan.Win32.Bayrob.bs (v)
TrendMicroTROJ_BAYROB.SM7
McAfee-GW-EditionBehavesLike.Win32.Trojan.hh
EmsisoftGen:Variant.Barys.58165 (B)
IkarusTrojan.Win32.Bayrob
GDataGen:Variant.Barys.58165
JiangminTrojan.Bayrob.wbs
AviraTR/Nivdort.Gen2
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.1888897
ArcabitTrojan.Barys.DE335
MicrosoftTrojanSpy:Win32/Nivdort
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.C1386802
Acronissuspicious
VBA32SScope.Malware-Cryptor.Bayrob
ALYacGen:Variant.Barys.58165
MalwarebytesTrojan.Bayrob.Generic
APEXMalicious
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazpvc2/VZwWbcorJaoId1mON)
YandexTrojan.GenAsa!Pa+nb2Emkkc
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bayrob.BT!tr
AVGFileRepMalware
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove SScope.Malware-Cryptor.Bayrob?

SScope.Malware-Cryptor.Bayrob removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment