Backdoor

What is “BScope.Backdoor.Sinowal”?

Malware Removal

The BScope.Backdoor.Sinowal is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Backdoor.Sinowal virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine BScope.Backdoor.Sinowal?


File Info:

name: 1C2B16B0E7B7BE8B2909.mlw
path: /opt/CAPEv2/storage/binaries/6d9f9e5d76961231b5e0a008a9eed84c4c220f45e524c8bb121297b159a45d13
crc32: 3FA7C93C
md5: 1c2b16b0e7b7be8b2909119813e953a8
sha1: 22a43abb6aa0183b6473e88453a73e3dc86c3335
sha256: 6d9f9e5d76961231b5e0a008a9eed84c4c220f45e524c8bb121297b159a45d13
sha512: cc9e75477bcd5efe33eb99589cbdaeb33cb4f10d44863254a77ee5fe25e71d8274d9af84132e3d84c9c8b8c73992488b50fd7de91aad68f4c8417bad2d420f43
ssdeep: 12288:DII8oKjSDd/TdqUDvSXw1oP/WvmcdK5rbzTTn+3Y:DgvmJ/LDvSg1kxrz/w
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T194B4C0027FFCC076CA0706329F99AFEAA4FA97964C60955317C40D5CFA35DC2D225E2A
sha3_384: db680fd6b63e7883bc6a162806e4c1dcebf6a7f2ca6f7ae541f6dcd169c7acc442d87f706f0fa629a8f2009fa1c153fa
ep_bytes: 558bec6aff6840ce430068b03d430064
timestamp: 2018-12-30 00:45:13

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7-Zip Console
FileVersion: 18.06
InternalName: 7z
LegalCopyright: Copyright (c) 1999-2018 Igor Pavlov
OriginalFilename: 7z.exe
ProductName: 7-Zip
ProductVersion: 18.06
Translation: 0x0409 0x04b0

BScope.Backdoor.Sinowal also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jaik.173903
ZillyaBackdoor.Sinowal.Win32.22183
SangforSuspicious.Win32.Save.ins
CyrenW32/Injuke.BI.gen!Eldorado
ESET-NOD32a variant of Win32/GenKryptik.GNTI
APEXMalicious
KasperskyVHO:Backdoor.Win32.Sinowal.gen
BitDefenderGen:Variant.Jaik.173903
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.11b62814
EmsisoftGen:Variant.Jaik.173903 (B)
VIPREGen:Variant.Jaik.173903
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.1c2b16b0e7b7be8b
SophosML/PE-A
IkarusTrojan.Crypt
GDataGen:Variant.Jaik.173903
MAXmalware (ai score=84)
Antiy-AVLGrayWare/Win32.Wacapew
ArcabitTrojan.Jaik.D2A74F
MicrosoftProgram:Win32/Wacapew.C!ml
GoogleDetected
AhnLab-V3Malware/Win.Generic.C5482209
BitDefenderThetaGen:NN.ZexaF.36662.Gy0@aW@M3Mmi
ALYacGen:Variant.Jaik.173903
VBA32BScope.Backdoor.Sinowal
Cylanceunsafe
RisingTrojan.Generic@AI.100 (RDML:UiFDppkPaG5Q3JE+v3IC2g)
FortinetAdware/Adware_AGen
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove BScope.Backdoor.Sinowal?

BScope.Backdoor.Sinowal removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment