Backdoor

What is “BScope.Backdoor.Rat”?

Malware Removal

The BScope.Backdoor.Rat is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Backdoor.Rat virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine BScope.Backdoor.Rat?


File Info:

crc32: 13F64E94
md5: 742d0fbf067bf70bb3857d52e32a14ee
name: 742D0FBF067BF70BB3857D52E32A14EE.mlw
sha1: 3f8224bcafcb3ada45e51904cec76985dc71492f
sha256: 00a43037570aef0f977589fa679bf79627d04890fabfca6c19ae2c2f851ef289
sha512: 5c1e458c842b8bf968d6903f1d8e9f368762801f41398c36c54881086e2f2b64c5b89d5dc510f3e809673670916883f1b4331880424423e705beb939431796a1
ssdeep: 24576:kJGpYoJedYXwPDf476OJSeQPo30ILeZj3W82dTfh8A:p2YXJgPImjmVdDh
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

BScope.Backdoor.Rat also known as:

DrWebBackDoor.Rat.281
MicroWorld-eScanTrojan.GenericKD.35718871
CAT-QuickHealBackdoor.Remcos
ALYacTrojan.GenericKD.35718871
CylanceUnsafe
K7AntiVirusTrojan-Downloader ( 0056205d1 )
BitDefenderTrojan.GenericKD.35718871
K7GWTrojan-Downloader ( 0056205d1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Trojan.LTEP-8313
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0WLI20
AvastWin32:Malware-gen
KasperskyHEUR:Backdoor.Win32.Remcos.gen
AlibabaTrojanDownloader:Win32/Rugmi.5d42ccea
ViRobotTrojan.Win32.Z.Rugmi.1038336
AegisLabTrojan.Win32.Remcos.m!c
Ad-AwareTrojan.GenericKD.35718871
SophosMal/Generic-S
ComodoMalware@#2e8q4l3vi243q
F-SecureTrojan.TR/AD.NsisInject.uqvft
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WLI20
McAfee-GW-EditionRDN/Generic Downloader.x
EmsisoftTrojan.GenericKD.35718871 (B)
IkarusTrojan-Downloader.Win32.Rugmi
JiangminBackdoor.Remcos.cin
AviraTR/AD.NsisInject.uqvft
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AA00
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Generic.D22106D7
ZoneAlarmHEUR:Backdoor.Win32.Remcos.gen
GDataTrojan.GenericKD.35718871
CynetMalicious (score: 85)
AhnLab-V3Malware/Win32.Generic.C4263564
McAfeeRDN/Generic Downloader.x
MAXmalware (ai score=85)
VBA32BScope.Backdoor.Rat
MalwarebytesTrojan.Downloader
PandaTrj/GdSda.A
ESET-NOD32Win32/TrojanDownloader.Rugmi.FAH
RisingTrojan.Injector!8.C4 (TFE:6:ELOmsxgwEfQ)
YandexTrojan.DL.Rugmi!ip5NasV8hf0
eGambitUnsafe.AI_Score_78%
FortinetW32/Rugmi.FAH!tr.dldr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.a07

How to remove BScope.Backdoor.Rat?

BScope.Backdoor.Rat removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment