Backdoor

BScope.Backdoor.Small removal

Malware Removal

The BScope.Backdoor.Small is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Backdoor.Small virus can do?

  • Sample contains Overlay data
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine BScope.Backdoor.Small?


File Info:

name: D641395B4A8B9BB6C73A.mlw
path: /opt/CAPEv2/storage/binaries/081fbc77f9f25b850001426591d4e3e0acc96426c3c9275b9b4c67e7913c38ad
crc32: 55E7C4E6
md5: d641395b4a8b9bb6c73a3d961fda41db
sha1: c3a040a9378d204dd2da9e9a670242940c670bf5
sha256: 081fbc77f9f25b850001426591d4e3e0acc96426c3c9275b9b4c67e7913c38ad
sha512: 36839f3452fe1aa03f52fb9e36d4e302a10711d448edb6185cf2c51a9fbe24842196723c0961ac3f44b3e1fd1b41920485b070050c94207e758475a351286520
ssdeep: 3072:nYUb5QoJ4g+riMY7p0GS6YtwM0MqRJWcfM+DZj6Iz1ZdW4Svq5MegHBnPRCBL:nYh7MCGScbzRJWyDh6SZI4+qpcZPRCp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11A7482562F8CE231DD70027F2CA916F9AED14BE9A22279C1D794D02F09DFB1419EF1A4
sha3_384: fbcbb08d14071fac21155aa9e34105d42df6adda5e656f52442e43aa5ca63cd9d71cad12cac069015e648b10c36fc9ea
ep_bytes: 6a00e821010100a3bc514100e81d0101
timestamp: 2013-09-24 23:04:52

Version Info:

0: [No Data]

BScope.Backdoor.Small also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Doina.9753
ALYacGen:Variant.Doina.9753
MalwarebytesGeneric.Trojan.Malicious.DDS
VIPREGen:Variant.Doina.9753
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 000002c61 )
K7GWTrojan ( 000002c61 )
Cybereasonmalicious.b4a8b9
VirITTrojan.Win32.Click.DWD
CyrenW32/Agent.FRV.gen!Eldorado
SymantecDownloader
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.UY
APEXMalicious
ClamAVWin.Trojan.Fugrafa-9733007-0
KasperskyBackdoor.Win32.Small.ml
BitDefenderGen:Variant.Doina.9753
NANO-AntivirusTrojan.Win32.Click.gacxgj
AvastWin32:Downloader-TH [Trj]
TencentBackdoor.Win32.Small.kc
EmsisoftGen:Variant.Doina.9753 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Click.2603
ZillyaBackdoor.Small.Win32.11061
TrendMicroTROJ_GEN.R03BC0CEL23
McAfee-GW-EditionBehavesLike.Win32.Generic.fm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.d641395b4a8b9bb6
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1620HTT
JiangminBackdoor.Small.ix
AviraTR/Dropper.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan[Backdoor]/Win32.Small
XcitiumTrojWare.Win32.Agent.ve@4yoq0p
ArcabitTrojan.Doina.D2619
ViRobotBackdoor.Win32.A.Small.80896
ZoneAlarmBackdoor.Win32.Small.ml
MicrosoftBackdoor:Win32/Small.IR
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win.Small.R566168
McAfeeGenericRXVQ-ZN!D641395B4A8B
VBA32BScope.Backdoor.Small
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0CEL23
RisingBackdoor.Small.hol (CLASSIC)
YandexBackdoor.Small!xiGZfFYv3b8
IkarusBackdoor.Win32.Small
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.U!tr
BitDefenderThetaGen:NN.ZexaF.36196.v8Z@auxt4pg
AVGWin32:Downloader-TH [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove BScope.Backdoor.Small?

BScope.Backdoor.Small removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment