Worm

BScope.Worm.Agent malicious file

Malware Removal

The BScope.Worm.Agent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Worm.Agent virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup

How to determine BScope.Worm.Agent?


File Info:

name: 23A186B9F6A9FAEE7488.mlw
path: /opt/CAPEv2/storage/binaries/1ad0d56ba6d17f058394c3b0045ed638aeb26a9d0c974832979471b16d372924
crc32: DBB6E79E
md5: 23a186b9f6a9faee7488dc6394f2924f
sha1: 560a044aabf8df4a66c9f99126f93673641cab94
sha256: 1ad0d56ba6d17f058394c3b0045ed638aeb26a9d0c974832979471b16d372924
sha512: cc2909aec9d48716806f9b2a2b9ff7bdd125b7307bf9826e3b8fac4215bc73b53ad598765bed91a7419cbf61e5f966ac1fa7bac4a61fd39325683324a7d56213
ssdeep: 1536:A3jWj+DOd5AJyWt0icToSHCMmvLsrny/pwFquLFUTQnN3R9M5WLiVwt3EJG:ATLoAJytFCMmDR/pqqsFUCN3R9MI+QE0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13093BFC03A85C43ED01A41795A89F53A5C38D67524218EC3EFD0EA59AFCD2B1A62C7B3
sha3_384: 925190a3d5b86b3124ab89ab7cd01863b8f2721061b62a6aa40150ff77a2a215937f71d4bae46e59440d243a6625dfc7
ep_bytes: 5589e56aff68dc18410068d85d400064
timestamp: 2006-03-02 17:50:37

Version Info:

0: [No Data]

BScope.Worm.Agent also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Malware.SPfVoPk!1!prn!.FE0B916D
FireEyeGeneric.mg.23a186b9f6a9faee
CAT-QuickHealWorm.Sfone.A3
ALYacGeneric.Malware.SPfVoPk!1!prn!.FE0B916D
CylanceUnsafe
ZillyaWorm.Agent.Win32.9
K7AntiVirusEmailWorm ( 00571eb41 )
K7GWEmailWorm ( 00571eb41 )
Cybereasonmalicious.9f6a9f
BitDefenderThetaAI:Packer.A4AAEA4E1E
CyrenW32/Worm.KOKR-0749
SymantecW32.SillyWNSE
ESET-NOD32a variant of Win32/Agent.CP
BaiduWin32.Worm.Agent.fj
ClamAVWin.Malware.Sfone-6763601-0
KasperskyHEUR:Trojan.Win32.Wofith.vho
BitDefenderGeneric.Malware.SPfVoPk!1!prn!.FE0B916D
NANO-AntivirusTrojan.Win32.Wofith.iariji
AvastWin32:Agent-URR [Trj]
TencentWorm.Win32.Agent.d
Ad-AwareGeneric.Malware.SPfVoPk!1!prn!.FE0B916D
SophosML/PE-A + Troj/Agent-BFWE
DrWebWin32.HLLW.Siggen.1607
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.mh
EmsisoftGeneric.Malware.SPfVoPk!1!prn!.FE0B916D (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Worm.Sfone.B
JiangminWorm.Agent.yh
AviraTR/Spy.Gen
Antiy-AVLTrojan/Generic.ASCommon.1C4
MicrosoftWorm:Win32/Sfone.A
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Agent.R233959
Acronissuspicious
McAfeeW32/Generic.worm.f
MAXmalware (ai score=87)
VBA32BScope.Worm.Agent
MalwarebytesWorm.Sform
APEXMalicious
RisingWorm.Agent!1.CEBD (CLASSIC)
YandexTrojan.GenAsa!2oUtO9JdH+o
IkarusWorm.Win32.Agent
FortinetW32/Agent.CP!worm
AVGWin32:Agent-URR [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove BScope.Worm.Agent?

BScope.Worm.Agent removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment