Backdoor

BScope.Backdoor.Pahak removal instruction

Malware Removal

The BScope.Backdoor.Pahak is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Backdoor.Pahak virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Starts servers listening on 0.0.0.0:6416
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine BScope.Backdoor.Pahak?


File Info:

name: B79E36ABFF7C07048C47.mlw
path: /opt/CAPEv2/storage/binaries/2f1493c83e72fc2dda906f058872a77400d37d904b5959eb561fe816560e84af
crc32: B2E52C25
md5: b79e36abff7c07048c478b51dad2fb33
sha1: 7a54fe685567dd91dddef0deb95338c51962ec33
sha256: 2f1493c83e72fc2dda906f058872a77400d37d904b5959eb561fe816560e84af
sha512: 8ddc316f3fabcb634b8d3769e492856c27dfdadc273ccd69a0297724a003e5637177c1f9792338e7bec3c67e024f76b4d41f074aef62e9ced98940b6899c8001
ssdeep: 6144:1+gXcQf8X5vybtf3vBjPHgITEfcIJ/gUNU31qefZz1XxQ+zJVQ77jwkbzKqNle:RMQfCybtvtgIFIVgUnshiCJVGfvPb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FDD42AAA77511073D1F6BD3E4B4F07F91D37AD502C207DC96AE488891BB8E44B80A66F
sha3_384: e4cdc43b9bf110f36ad7eefe0d67a078ebbf0326990bd1edcd04fead5a8fe45a35f0c7b85c9743548f1a3e6f16997242
ep_bytes: 558bec83c4f0b87ccf4600e80499f9ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

BScope.Backdoor.Pahak also known as:

K7AntiVirusTrojan ( 7000000f1 )
K7GWTrojan ( 7000000f1 )
APEXMalicious
SophosMal/Generic-S
IkarusTrojan-Dropper.Delf
GridinsoftRansom.Win32.Sabsik.sa
McAfeeArtemis!B79E36ABFF7C
VBA32BScope.Backdoor.Pahak
MaxSecureTrojan.Malware.300983.susgen

How to remove BScope.Backdoor.Pahak?

BScope.Backdoor.Pahak removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment