Backdoor Spy

BScope.Backdoor.Spy removal tips

Malware Removal

The BScope.Backdoor.Spy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Backdoor.Spy virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine BScope.Backdoor.Spy?


File Info:

crc32: 10AC3F3C
md5: 8c031614bd41049acb17a6d55770e329
name: cbkol.exe
sha1: 92157c546cfb9a53de9821cbbce508932d121c7f
sha256: f061b5abab544f814981ac8a268385a04aba00187a632d9c82f201835a0e97fc
sha512: 932f9b3a225a0aecbe1ebe634da3b9f9b7a04f96ed2f9ab78e5372c43566d00e5bee954131d9ba1fc66771506fa0cecdcb741e7d1c65c408aee9bc3fd7b8c0c7
ssdeep: 3072:4d9SByLUv8aRohXifKjDZoWrKrE0/eVDzbZ4Vbqgn5CV7AphztVsL8jIwzwout:4cPvHoofKRoCKQ0cDzbiYG5+7qRzjzw
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

FileVersion: 1.1.6.9
ProductVersion: 1.1.6.9
Translation: 0x0804 0x04b0

BScope.Backdoor.Spy also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Graftor.285431
CAT-QuickHealTrojan.Tiggre
McAfeeArtemis!8C031614BD41
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 004d35661 )
BitDefenderGen:Variant.Graftor.285431
K7GWTrojan ( 004d35661 )
CrowdStrikewin/malicious_confidence_80% (W)
Invinceaheuristic
BaiduWin32.Trojan.Idsohtu.h
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
GDataGen:Variant.Graftor.285431
AlibabaTrojan:Win32/Idsohtu.2873d770
NANO-AntivirusTrojan.Win32.Idsohtu.flnxud
AegisLabTrojan.Win32.Idsohtu.4!c
RisingTrojan.Idsohtu!8.4AC (TFE:5:7R0OdhDFg9K)
Ad-AwareGen:Variant.Graftor.285431
EmsisoftGen:Variant.Graftor.285431 (B)
F-SecureTrojan.TR/Idsohtu.xslwv
DrWebBackDoor.Spy.3627
ZillyaTrojan.Idsohtu.Win32.150
TrendMicroTROJ_GEN.R015C0PJR19
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
FireEyeGeneric.mg.8c031614bd41049a
SophosMal/Generic-S
IkarusTrojan.Win32.Idsohtu
AviraTR/Idsohtu.xslwv
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Tiggre
Endgamemalicious (moderate confidence)
ArcabitTrojan.Graftor.D45AF7
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Malware/Win32.Generic.C2899307
Acronissuspicious
BitDefenderThetaAI:Packer.48F2033C1F
ALYacTrojan.Agent.Casur
VBA32BScope.Backdoor.Spy
CylanceUnsafe
ESET-NOD32a variant of Win32/Idsohtu.I
TrendMicro-HouseCallTROJ_GEN.R015C0PJR19
TencentMalware.Win32.Gencirc.10b450b8
YandexTrojan.Idsohtu!
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Idsohtu.I!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.453

How to remove BScope.Backdoor.Spy?

BScope.Backdoor.Spy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment