Adware Reports malware removal guides and threat research Updated security instructions for Windows users
Threat report

BScope.TrojanSpy.Nivdort removal

Published Apr 28, 2024 Spy category 3 min read
Report context

What to verify before removal

BScope.TrojanSpy.Nivdort removal deserves a credential-safety review because this spy label can overlap with remote access, browser data theft, or persistence after reboot. Cleanup should include scanning the file, removing the persistence point, and rotating exposed passwords from a clean device.

Start by comparing the local file name with 4253754774FB998CE2B7.mlw, then review the behavior notes for credential theft, browser data access, remote-control activity, and persistence after reboot. This helps separate a matching detection from a different file that only shares a similar alert name.

Observed file
4253754774FB998CE2B7.mlw
  • Compare the suspicious file name with 4253754774FB998CE2B7.mlw.
  • Confirm the detection name matches BScope.TrojanSpy.Nivdort removal before removing related files.
  • Review the report for credential theft, browser data access, remote-control activity, and persistence after reboot so the cleanup is based on observed behavior, not only the label.
  • After cleanup, rotate passwords from a clean device and review browser sessions or saved credentials.

The BScope.TrojanSpy.Nivdort is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What BScope.TrojanSpy.Nivdort virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine BScope.TrojanSpy.Nivdort?


File Info:

name: 4253754774FB998CE2B7.mlw
path: /opt/CAPEv2/storage/binaries/2d8b096783e45349aaebbec56214ca52d95934a4a6dc66cd53a15455dfe6ea7e
crc32: FBE089EF
md5: 4253754774fb998ce2b7f69542c8d73d
sha1: ef926e58e312326c452d98ef266713be19035615
sha256: 2d8b096783e45349aaebbec56214ca52d95934a4a6dc66cd53a15455dfe6ea7e
sha512: 8c72215c4c9a85df230e943b24fb058566fdf16d663529f6b2b482ad566eb2b15f23b78b0c7985c9170356734bc8b7cde5312b85f74ef17403a3f298edcf1c43
ssdeep: 6144:+0B/iYtgANgHMrVr8Hul5qnFmza0pezs8/MYZy32eVclxsdCu/NvLr0W3VeKl4b+:+7YWrOine9zVcLk/3T4bt7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CE7407ECEE90C1DACC92647A01172BB3D77D104436D6A5C792F03748EBBD9A5EA3060B
sha3_384: 46bf52ebd187658389a36bed66177d08e5469df4399e443ce24f91e19060bd561eda6cc7e1b3239fc437dfec97f0e386
ep_bytes: 558bec83ec08dd05a8c3440056d9e8dc
timestamp: 2015-12-23 04:35:43

Version Info:

0: [No Data]

BScope.TrojanSpy.Nivdort also known as:

Bkav W32.AIDetectMalware
AVG Win32:Evo-gen [Trj]
DrWeb Trojan.DownLoader18.36706
MicroWorld-eScan Gen:Variant.Razy.11545
FireEye Generic.mg.4253754774fb998c
CAT-QuickHeal TrojanSpy.Nivdort.DR3
Skyhigh BehavesLike.Win32.Generic.fh
McAfee Trojan-FHPD!4253754774FB
VIPRE Gen:Variant.Razy.11545
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 004db0c61 )
K7GW Trojan ( 004da1e61 )
BitDefenderTheta AI:Packer.BBDF484F1E
Symantec Trojan.Bayrob!gen6
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Bayrob.AQ
Cynet Malicious (score: 100)
APEX Malicious
ClamAV Win.Trojan.Agent-1369972
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Gen:Variant.Razy.11545
NANO-Antivirus Trojan.Win32.Dwn.dzovhg
Avast Win32:Evo-gen [Trj]
Rising Trojan.Bayrob!1.A350 (CLASSIC)
Emsisoft Gen:Variant.Razy.11545 (B)
F-Secure Trojan.TR/Nivdort.Gen2
Zillya Trojan.Bayrob.Win32.3698
TrendMicro TROJ_BAYROB.SM1
Trapmine malicious.high.ml.score
Sophos Troj/Nivdort-CZ
Ikarus Trojan.Win32.Bayrob
Jiangmin Trojan.Generic.jbtk
Varist W32/Nivdort.F.gen!Eldorado
Avira TR/Nivdort.Gen2
Antiy-AVL Trojan/Win32.AGeneric
Kingsoft malware.kb.a.993
Microsoft TrojanSpy:Win32/Nivdort.CW
Arcabit Trojan.Razy.D2D19
ZoneAlarm HEUR:Trojan.Win32.Generic
GData Gen:Variant.Razy.11545
Google Detected
AhnLab-V3 Trojan/Win32.Agent.R170875
VBA32 BScope.TrojanSpy.Nivdort
ALYac Gen:Variant.Razy.11545
Cylance unsafe
Panda Trj/Genetic.gen
TrendMicro-HouseCall TROJ_BAYROB.SM1
Tencent Malware.Win32.Gencirc.10b5e2fa
Yandex Trojan.GenAsa!R3lDFHcfsC4
MAX malware (ai score=82)
Fortinet W32/Bayrob.AQ!tr
DeepInstinct MALICIOUS

How to remove BScope.TrojanSpy.Nivdort?

Recommended second-opinion scan

Verify the infection before changing system settings

Use GridinSoft Anti-Malware to run a full scan, review detected persistence entries, and quarantine confirmed threats before restarting Windows.

Download GridinSoft Anti-Malware
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.