Malware

BScope.Exploit.CVE-2016-7255 removal guide

Malware Removal

The BScope.Exploit.CVE-2016-7255 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Exploit.CVE-2016-7255 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

ipv4bot.whatismyipaddress.com
ns1.wowservers.ru
carder.bit
ns2.wowservers.ru
ransomware.bit

How to determine BScope.Exploit.CVE-2016-7255?


File Info:

crc32: 4A5BE2CE
md5: f93df2feaa8159ff9864c28ae2ea0c82
name: F93DF2FEAA8159FF9864C28AE2EA0C82.mlw
sha1: 2abd9bbd368840e2f090ce3a6a99fd079c2c1e63
sha256: 4da84d8fb1f3bc804f5869968feebd42d38d0380234b2d1e738ba4c8d029d4e0
sha512: 3022c764eae40a97aa92df67e9c0055bdc3bf80b255d1a84007982209fbd64078e345bf57bb1928ede9abaca20027c7da86948eeaa7f95758b8ff5cfd8a37723
ssdeep: 6144:VAI99RCzR3LeqUrY1ZEgnl45Pe11n1XbkqL:VT99RW3dUM+845Unn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

BScope.Exploit.CVE-2016-7255 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.GandCrab.Gen.2
FireEyeGeneric.mg.f93df2feaa8159ff
CAT-QuickHealTrojan.Chapak.ZZ5
McAfeeGenericRXFF-YY!F93DF2FEAA81
MalwarebytesTrojan.MalPack
VIPRETrojan.Win32.Generic!BT
SangforWin.Packed.Gandcrab-6520432-4
K7AntiVirusTrojan ( 003e58dd1 )
BitDefenderTrojan.Ransom.GandCrab.Gen.2
K7GWTrojan ( 655333331 )
Cybereasonmalicious.eaa815
BitDefenderThetaGen:NN.ZexaF.34590.suX@ai!gfWk
CyrenW32/Gandcrab.HOIG-0752
SymantecPacked.Generic.525
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Gandcrab-6520432-4
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.NgrBot.fbains
ViRobotTrojan.Win32.GandCrab.Gen.A
Ad-AwareTrojan.Ransom.GandCrab.Gen.2
TACHYONRansom/W32.GandCrab
EmsisoftTrojan.Ransom.GandCrab.Gen.2 (B)
ComodoApplication.Win32.IStartSurf.PS@8c4m91
F-SecureHeuristic.HEUR/AGEN.1102735
ZillyaTrojan.Scar.Win32.110213
SophosML/PE-A + Mal/Agent-AUL
IkarusTrojan.Kryptik
JiangminTrojanDownloader.Upatre.ajee
AviraHEUR/AGEN.1102735
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftRansom:Win32/Gandcrab
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.GandCrab.Gen.2
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Gandcrab.Exp
Acronissuspicious
VBA32BScope.Exploit.CVE-2016-7255
ALYacTrojan.Ransom.GandCrab.Gen.2
MAXmalware (ai score=100)
TrendMicro-HouseCallRansom.Win32.GANDCRAB.SMLA.hp
TencentMalware.Win32.Gencirc.10b80102
YandexTrojan.GenAsa!oJVYVP7lADk
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_66%
FortinetW32/Kryptik.GKTH!tr.ransom
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Exploit.7b9

How to remove BScope.Exploit.CVE-2016-7255?

BScope.Exploit.CVE-2016-7255 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment