Backdoor

BScope.Backdoor.CoreBot information

Malware Removal

The BScope.Backdoor.CoreBot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Backdoor.CoreBot virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time

How to determine BScope.Backdoor.CoreBot?


File Info:

crc32: 6914401B
md5: b70e07ba658852e17aea25c7a4003df1
name: B70E07BA658852E17AEA25C7A4003DF1.mlw
sha1: e8ae17179c1a1b43a2ee19c0a7e24aca2b3847c7
sha256: 747ccabb38ff83a22d753e16e87e198579b12e7a033000e72cb02e9eb1c428c1
sha512: 49ef9a7b2c06ccd5bca68b86783f0b453e917f5f6eef45c479f1451e1421fb170fb4cd8a93c8526e280c77b65d6a6c423d7e2b24a15e44985b2c5a259ff6eef0
ssdeep: 12288:gShSkWpwbOHnNJZLubwK7gtgyF8yxiTcm7D7CYP:gOSkWoyNJ0zyx+v
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017, dfgjdhf
FileVersion: 11.0.0.1
ProductVersion: 11.0.0.1
Translation: 0x0809 0x04b0

BScope.Backdoor.CoreBot also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 00539ed31 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24120
MicroWorld-eScanTrojan.BRMon.Gen.1
CAT-QuickHealTrojan.Chapak.ZZ6
McAfeeTrojan-FOXF!B70E07BA6588
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWAdware ( 00539ed31 )
Cybereasonmalicious.a65885
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.HHLN
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
BitDefenderTrojan.BRMon.Gen.1
NANO-AntivirusTrojan.Win32.Jorik.ewrbhi
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
TencentWin32.Trojan.Jorik.Pdcg
Ad-AwareTrojan.BRMon.Gen.1
ComodoTrojWare.Win32.Crypt.BF@7gchou
BitDefenderThetaGen:NN.ZexaF.34670.Jy0@aOUMGcl
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPGANDCRAB.SMONT
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
FireEyeGeneric.mg.b70e07ba658852e1
EmsisoftTrojan.BRMon.Gen.1 (B)
AviraHEUR/AGEN.1115408
eGambitUnsafe.AI_Score_80%
MicrosoftRansom:Win32/Ergop
AegisLabTrojan.Win32.Jorik.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.BRMon.Gen.1
AhnLab-V3Trojan/Win32.MalCrypted.R221070
Acronissuspicious
VBA32BScope.Backdoor.CoreBot
MAXmalware (ai score=85)
MalwarebytesRansom.FileCryptor
PandaTrj/CI.A
TrendMicro-HouseCallRansom_HPGANDCRAB.SMONT
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexTrojan.GenAsa!5W1STy+utjA
SentinelOneStatic AI – Malicious PE
MaxSecureRansomeware.GandCrypt.Gen
FortinetW32/Kryptik.FYNO!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HwoCEpsA

How to remove BScope.Backdoor.CoreBot?

BScope.Backdoor.CoreBot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment