Malware

TScope.Malware-Cryptor.SB removal instruction

Malware Removal

The TScope.Malware-Cryptor.SB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What TScope.Malware-Cryptor.SB virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine TScope.Malware-Cryptor.SB?


File Info:

crc32: B27B0D34
md5: 108ea07190490f1b30f6be2f212c2932
name: sokge.exe
sha1: f33c9de8bf35827bdc00d568064991449829f694
sha256: bc8740f5f6372fdd41dc920c8e4d9edbc7629dca04a755fc6e6ff07e7b154f45
sha512: 7560c47026ec2512e9288626dca3dd9ef658b2dff4982e1596e269bdf7f397bd68907d9dfd8f64a6cc2137f94d2069d8e46fff9c6005f021d050a36eb4302032
ssdeep: 3072:EOC6aND4lk+ukCvE0IdPqmHgbeCEZ25hTB9dJ9WQDN+8V6I7XYVRuLljt84vO4O:E/fkmfkCMpomA1Ej2sk7XhGN1o
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2008 Free Software Foundation
InternalName: wget
FileVersion: 1.11.4.3287
License: This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License; see www.gnu.org/copyleft/gpl.html.
CompanyName: GnuWin32
PrivateBuild: Patchlevel 1
LegalTrademarks: GnuWin32xae, Wgetxae, wgetxae
WWW: http://www.gnu.org/software/wget
ProductName: Wget
ProductVersion: 1.11.4.3287
FileDescription: Wget: retrieve files from the WWW
OriginalFilename: wget.exe
Translation: 0x0409 0x04e4

TScope.Malware-Cryptor.SB also known as:

MicroWorld-eScanTrojan.GenericKD.32633121
CAT-QuickHealTrojan.Fuery
ALYacTrojan.Proxy.Sybici
MalwarebytesTrojan.Downloader
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.32633121
K7GWRiskware ( 0040eff71 )
TrendMicroTROJ_GEN.R002C0WJP19
BitDefenderThetaGen:NN.ZexaF.32251.iC0@aGUyv2ci
CyrenW32/Trojan.ZMGZ-7871
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.GVMZ
TrendMicro-HouseCallTROJ_GEN.R002C0WJP19
Paloaltogeneric.ml
GDataTrojan.GenericKD.32633121
KasperskyTrojan-Proxy.Win32.Sybici.ft
AlibabaTrojanProxy:Win32/Sybici.a0b7e9dc
NANO-AntivirusTrojan.Win32.Sybici.geokgu
AegisLabTrojan.Win32.Sybici.h!c
RisingTrojan.Generic@ML.96 (RDMK:6WxK8MuzfgrbmhixfbG4ig)
Ad-AwareTrojan.GenericKD.32633121
EmsisoftTrojan.GenericKD.32633121 (B)
ComodoMalware@#33bkfltu7sw1b
F-SecureTrojan.TR/AD.Coroxy.stlny
DrWebTrojan.DownLoader30.29539
ZillyaTrojan.Kryptik.Win32.1800047
McAfee-GW-EditionRDN/Generic.dx
FireEyeTrojan.GenericKD.32633121
SophosMal/Generic-S
APEXMalicious
JiangminTrojanProxy.Sybici.t
WebrootW32.Trojan.Gen
AviraTR/AD.Coroxy.stlny
MAXmalware (ai score=85)
ArcabitTrojan.Generic.D1F1F121
ZoneAlarmTrojan-Proxy.Win32.Sybici.ft
MicrosoftTrojan:Win32/Skeeyah.A!MTB
AhnLab-V3Malware/Win32.Generic.C3545665
McAfeeRDN/Generic.dx
VBA32TScope.Malware-Cryptor.SB
CylanceUnsafe
PandaGeneric Malware
YandexTrojan.PR.Sybici!
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.GVMZ!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Proxy.637

How to remove TScope.Malware-Cryptor.SB?

TScope.Malware-Cryptor.SB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment