Spy Trojan

BScope.TrojanSpy.Nivdort removal

Malware Removal

The BScope.TrojanSpy.Nivdort is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.TrojanSpy.Nivdort virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine BScope.TrojanSpy.Nivdort?


File Info:

name: 4253754774FB998CE2B7.mlw
path: /opt/CAPEv2/storage/binaries/2d8b096783e45349aaebbec56214ca52d95934a4a6dc66cd53a15455dfe6ea7e
crc32: FBE089EF
md5: 4253754774fb998ce2b7f69542c8d73d
sha1: ef926e58e312326c452d98ef266713be19035615
sha256: 2d8b096783e45349aaebbec56214ca52d95934a4a6dc66cd53a15455dfe6ea7e
sha512: 8c72215c4c9a85df230e943b24fb058566fdf16d663529f6b2b482ad566eb2b15f23b78b0c7985c9170356734bc8b7cde5312b85f74ef17403a3f298edcf1c43
ssdeep: 6144:+0B/iYtgANgHMrVr8Hul5qnFmza0pezs8/MYZy32eVclxsdCu/NvLr0W3VeKl4b+:+7YWrOine9zVcLk/3T4bt7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CE7407ECEE90C1DACC92647A01172BB3D77D104436D6A5C792F03748EBBD9A5EA3060B
sha3_384: 46bf52ebd187658389a36bed66177d08e5469df4399e443ce24f91e19060bd561eda6cc7e1b3239fc437dfec97f0e386
ep_bytes: 558bec83ec08dd05a8c3440056d9e8dc
timestamp: 2015-12-23 04:35:43

Version Info:

0: [No Data]

BScope.TrojanSpy.Nivdort also known as:

BkavW32.AIDetectMalware
AVGWin32:Evo-gen [Trj]
DrWebTrojan.DownLoader18.36706
MicroWorld-eScanGen:Variant.Razy.11545
FireEyeGeneric.mg.4253754774fb998c
CAT-QuickHealTrojanSpy.Nivdort.DR3
SkyhighBehavesLike.Win32.Generic.fh
McAfeeTrojan-FHPD!4253754774FB
VIPREGen:Variant.Razy.11545
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004db0c61 )
K7GWTrojan ( 004da1e61 )
BitDefenderThetaAI:Packer.BBDF484F1E
SymantecTrojan.Bayrob!gen6
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Bayrob.AQ
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Agent-1369972
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.11545
NANO-AntivirusTrojan.Win32.Dwn.dzovhg
AvastWin32:Evo-gen [Trj]
RisingTrojan.Bayrob!1.A350 (CLASSIC)
EmsisoftGen:Variant.Razy.11545 (B)
F-SecureTrojan.TR/Nivdort.Gen2
ZillyaTrojan.Bayrob.Win32.3698
TrendMicroTROJ_BAYROB.SM1
Trapminemalicious.high.ml.score
SophosTroj/Nivdort-CZ
IkarusTrojan.Win32.Bayrob
JiangminTrojan.Generic.jbtk
VaristW32/Nivdort.F.gen!Eldorado
AviraTR/Nivdort.Gen2
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.993
MicrosoftTrojanSpy:Win32/Nivdort.CW
ArcabitTrojan.Razy.D2D19
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.11545
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R170875
VBA32BScope.TrojanSpy.Nivdort
ALYacGen:Variant.Razy.11545
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_BAYROB.SM1
TencentMalware.Win32.Gencirc.10b5e2fa
YandexTrojan.GenAsa!R3lDFHcfsC4
MAXmalware (ai score=82)
FortinetW32/Bayrob.AQ!tr
DeepInstinctMALICIOUS

How to remove BScope.TrojanSpy.Nivdort?

BScope.TrojanSpy.Nivdort removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment