Trojan

How to remove “BScope.Trojan.Kolovorot”?

Malware Removal

The BScope.Trojan.Kolovorot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Trojan.Kolovorot virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine BScope.Trojan.Kolovorot?


File Info:

name: 78470333271F5A8A9C4D.mlw
path: /opt/CAPEv2/storage/binaries/4369932bf2f0bb760b1ec78310aa11e247ca2cf9eae9c5f6c38a08664e572de3
crc32: 46695F50
md5: 78470333271f5a8a9c4d98e1bb0ec0d1
sha1: c5301f06b3ace6810df02b61a1dc1f75a6d5e858
sha256: 4369932bf2f0bb760b1ec78310aa11e247ca2cf9eae9c5f6c38a08664e572de3
sha512: 048255e9521d79a291f80810ada4f8f332bfd16ac45d45f1acb577111c1f1f61984999cd91168c69f4106eb672928041989f0295abafbe68e8820ebf718ace93
ssdeep: 24576:/vGMkKCmyt2aJAPoAjO4zSqPLbi9JgUqUbkI/I6/gGonQ/QsHFQ:/dNkAQPh7bonQ/QyFQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T170658D01F762C8F1D126227480F6577295708D6A0A25DBDBF358FD59BF33291882FA2B
sha3_384: 37b50a9b2769bbb8305d1f7a853ee2630c028fdfe3badf3114e0e61bfbd3ca4b3ed58648e9641b4e2bb167364ffdf4c8
ep_bytes: 558bec6aff68d0895200681425470064
timestamp: 2012-04-21 17:45:44

Version Info:

0: [No Data]

BScope.Trojan.Kolovorot also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.Click2.61116
ClamAVWin.Malware.Zusy-6717397-0
FireEyeGeneric.mg.78470333271f5a8a
MalwarebytesGeneric.Malware.AI.DDS
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaGen:NN.ZexaCO.36662.CrW@aKflZKob
CyrenW32/FlyStudio.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
F-SecureTrojan.TR/Agent.10752.DP
McAfee-GW-EditionBehavesLike.Win32.Generic.th
Trapminemalicious.moderate.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Application.PSE.1THOGOA
AviraTR/Agent.10752.DP
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumWorm.Win32.Dropper.RA@1qraug
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
VBA32BScope.Trojan.Kolovorot
Cylanceunsafe
RisingBackdoor.Farfli!1.6542 (CLASSIC)
IkarusTrojan-Dropper.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.PHP!tr
Cybereasonmalicious.6b3ace
DeepInstinctMALICIOUS

How to remove BScope.Trojan.Kolovorot?

BScope.Trojan.Kolovorot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment