Backdoor

BScope.Backdoor.Singu removal

Malware Removal

The BScope.Backdoor.Singu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Backdoor.Singu virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine BScope.Backdoor.Singu?


File Info:

name: A7F07413F96F15E9BFD3.mlw
path: /opt/CAPEv2/storage/binaries/6d4837bae8cd7fe2276d7c8b13f9a4ef9c9fd545d99bcd67dba344c89bc559cf
crc32: 4E65759C
md5: a7f07413f96f15e9bfd3357c78cb3586
sha1: 6c2e55e8bc9b692c65d5b36e93eb26c4e4fba5fd
sha256: 6d4837bae8cd7fe2276d7c8b13f9a4ef9c9fd545d99bcd67dba344c89bc559cf
sha512: e23d3d80911eaf76626d7581f30178bf43167e8bf65762d2af462d1e1d26ab24d9bd8e49791ccbfe19934d2d02987f2c23dc9075ffd5f0031d92b1d73258d5eb
ssdeep: 6144:s029ALg08ExXYQU5TvilaiCJF9jlsdAYJyRQcsJeZJ:sn9YC8XLUlvilaiSQxyRGQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F924120E7A189538F591CA7168DAAF362B736C033BB1C5AD366571BE0E367080D1CEE5
sha3_384: 411903e145b009fe7e76d9eabf648bdadbc65660f80eeea374c94d35452c6b70ed879ec1572f915f43d91b46b0580408
ep_bytes: b8f4634a005064ff3500000000648925
timestamp: 2012-03-18 19:30:14

Version Info:

CompanyName: LiHuiyusoft Co., Ltd.
FileDescription: USBKey
FileVersion: 1.0.1.3
InternalName: UKey
LegalCopyright: (C) LiHuiyusoft Corporation. All rights reserved.
LegalTrademarks: Lihuiyu Stdio Labs.
OriginalFilename: UKey.exe
ProductName:
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0804 0x03a8

BScope.Backdoor.Singu also known as:

BkavW32.AIDetectMalware
FireEyeGeneric.mg.a7f07413f96f15e9
SangforTrojan.Win32.Agent.Vskm
Cybereasonmalicious.8bc9b6
TrendMicro-HouseCallTROJ_GEN.R002H06BI23
McAfee-GW-EditionRDN/Generic.dx
Trapminemalicious.high.ml.score
Antiy-AVLTrojan/Win32.SGeneric
AhnLab-V3Malware/Win.Generic.C5153786
VBA32BScope.Backdoor.Singu
APEXMalicious
FortinetPossibleThreat.PALLAS.H
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (W)

How to remove BScope.Backdoor.Singu?

BScope.Backdoor.Singu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment