Backdoor

BScope.Backdoor.Attack (file analysis)

Malware Removal

The BScope.Backdoor.Attack is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Backdoor.Attack virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Attempts to repeatedly call a single API many times in order to delay analysis time

How to determine BScope.Backdoor.Attack?


File Info:

crc32: 480BCB6B
md5: e943142d9982ea0b52f6029a92611fd7
name: E943142D9982EA0B52F6029A92611FD7.mlw
sha1: 94099f4bda7dc6ed9ce04bd0e10ea61c10bffaaf
sha256: 9ea7c733a071226737d198ffb155c4162e802086c42da169109732715bf2923b
sha512: 1128929a9b13cdc5d989354eb2b2072574fed60c61e5ace99c7403550cc4a30e0c104bf308d772c653dea2b8de1e0714cda1e1aca79c6e5b815c9fae21f1d2d6
ssdeep: 24576:NhaktlTPB+yyEX+IhqiTyce7xDprgz76Jw0tIqyiN:NckXTp+92qvcoprGmh7y
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

BScope.Backdoor.Attack also known as:

K7AntiVirusAdware ( 004b8da51 )
MicroWorld-eScanTrojan.GenericKD.32248373
ALYacTrojan.GenericKD.32248373
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaPacked:Win32/VMProtect.967e0d30
K7GWAdware ( 004b8da51 )
Cybereasonmalicious.bda7dc
TrendMicroTROJ_GEN.R011C0RHK19
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.VMProtect.ABO
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.32248373
BitDefenderTrojan.GenericKD.32248373
Ad-AwareTrojan.GenericKD.32248373
SophosMal/VMProtBad-A
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
F-SecureTrojan.TR/Black.Gen2
ZillyaTrojan.Packed.Win32.167364
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.e943142d9982ea0b
EmsisoftTrojan.GenericKD.32248373 (B)
SentinelOneDFI – Malicious PE
Endgamemalicious (high confidence)
AviraTR/Black.Gen2
MicrosoftTrojan:Win32/Tiggre!plock
JiangminPacked.Vemply.ewr
ArcabitTrojan.Generic.D1EC1235
AegisLabTrojan.Win32.Malicious.4!c
Acronissuspicious
McAfeeArtemis!E943142D9982
MAXmalware (ai score=88)
VBA32BScope.Backdoor.Attack
TrendMicro-HouseCallTROJ_GEN.R011C0RHK19
RisingTrojan.Generic@ML.98 (RDMK:pGzb5zF3/+XAI2ImgIyEwg)
IkarusTrojan.Win32.VMProtect
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VMProtBad.A!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.6a2

How to remove BScope.Backdoor.Attack?

BScope.Backdoor.Attack removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment