Backdoor

Should I remove “BScope.Backdoor.BlackHole”?

Malware Removal

The BScope.Backdoor.BlackHole is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Backdoor.BlackHole virus can do?

  • Executable code extraction
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Collects information to fingerprint the system

Related domains:

xdx.s4f5er4t5g1df23saadse.club
fk.openyourass.icu

How to determine BScope.Backdoor.BlackHole?


File Info:

crc32: B2B182B7
md5: cd6249c0eae4d3d0b63de80ee6e22e01
name: download.exe
sha1: 1904455d4d7641b5cbb9062b62cd77dbe1cf4b72
sha256: 31dcda7af03c4d887cc77e1ccc8162e459c7e4127cdf9c39964e55f86988d6f7
sha512: 0dc389739859ccd7035920449fc298f724a2bd1d5ea5363dfb03ca0de7fc6e183d67cc3dab092ff784e19555c27903713e4f81920ae9cbe5faf53c6197d9fe80
ssdeep: 1536:RgiCmqUA6ekUWmwZzCIEfe4ZmszRkFMMuqiYisHNuvFzXLfJcn6Yss4muZjA:xqsUaZz5ESmSMnUNSFviLEm0
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

BScope.Backdoor.BlackHole also known as:

DrWebTrojan.DownLoader25.10311
MicroWorld-eScanGen:Trojan.Downloader.fmGfayOvMkcj
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeGenericRXIW-DU!5F2C130B9450
SangforMalware
BitDefenderGen:Trojan.Downloader.fmGfayOvMkcj
Cybereasonmalicious.0eae4d
TrendMicroBackdoor.Win32.ZEGOST.SMS
BitDefenderThetaGen:NN.ZexaF.33558.fmGfayOvMkcj
CyrenW32/Blackmoon.M.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Gh0stRAT-6989861-0
KasperskyTrojan.Win32.Siscos.wgv
RisingBackdoor.Zegost!8.177 (TFE:5:GhyWtHWPdCV)
Ad-AwareGen:Trojan.Downloader.fmGfayOvMkcj
SophosTroj/Agent-AWJO
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureHeuristic.HEUR/AGEN.1014775
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Trojan.nc
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.cd6249c0eae4d3d0
EmsisoftGen:Trojan.Downloader.fmGfayOvMkcj (B)
SentinelOneDFI – Malicious PE
F-ProtW32/Blackmoon.M.gen!Eldorado
JiangminTrojan.Siscos.kx
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1014775
MicrosoftVirTool:Win32/CeeInject.SN!bit
Endgamemalicious (moderate confidence)
ArcabitTrojan.Downloader.fmGfayOvMkcj
ZoneAlarmTrojan.Win32.Siscos.wgv
GDataWin32.Trojan.Agent.WP
AhnLab-V3Trojan/Win32.Kryptik.R265106
Acronissuspicious
VBA32BScope.Backdoor.BlackHole
ALYacGen:Trojan.Downloader.fmGfayOvMkcj
MAXmalware (ai score=89)
CylanceUnsafe
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/TrojanDownloader.Tiny.NQG
TrendMicro-HouseCallBackdoor.Win32.ZEGOST.SMS
IkarusTrojan-Ransom.HydraCrypt
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.FHSF!tr
AVGWin32:DropperX-gen [Drp]
AvastWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.ee5

How to remove BScope.Backdoor.BlackHole?

BScope.Backdoor.BlackHole removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment