Worm

BScope.Worm.MSIL.Agent removal instruction

Malware Removal

The BScope.Worm.MSIL.Agent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Worm.MSIL.Agent virus can do?

  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine BScope.Worm.MSIL.Agent?


File Info:

name: 5948421EB390271D2284.mlw
path: /opt/CAPEv2/storage/binaries/248d2daf7aa4e9225fefbb99eabf297aee2d50167b1f258a104eab714635a371
crc32: 48F95AAD
md5: 5948421eb390271d2284032e8e0a53d4
sha1: ff2ca17a4c6bc0cd9fdbd7ab9047dc6d5e9ad58e
sha256: 248d2daf7aa4e9225fefbb99eabf297aee2d50167b1f258a104eab714635a371
sha512: 586bb8ed5ef41c606cd96c1e15e1347f5ffe5cda976bf3c6926bce57fb238b058d8ebb067d80cded9aadf49343ca05184cfa4e9369be34859ec06893ffee85a4
ssdeep: 12288:oPvva2rQ9KbFwOKpOz5N9vWst3QVkBNhw6Y5o+SudAfh39z2Go:oP6EQkbvK8N3t3QVkLhoo+SVfhl2/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15C451291B3D96480E5778E7688748830886BFC999DA4CD0F73E4360E8576BE09875F3B
sha3_384: f8789372b869b15d7d11a173278606bef5356bc0f65a6861742bd4ae92ba37f9078971570049a25430a9ba94b19c524c
ep_bytes: e87b050000e97afeffff558bec56ff75
timestamp: 2020-12-09 13:25:31

Version Info:

CompanyName: Oracle Corporation
FileDescription: Java Control Panel
FileVersion: 11.281.2.09
Full Version: 11.281.2.09
InternalName: Java Control Panel
LegalCopyright: Copyright © 2020
OriginalFilename: javacpl.exe
ProductName: Java(TM) Platform SE 8 U281
ProductVersion: 8.0.2810.9
Translation: 0x0409 0x04b0

BScope.Worm.MSIL.Agent also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebWin32.Expiro.158
MicroWorld-eScanWin32.Expiro.Gen.7
CAT-QuickHealW32.Expiro.R3
SkyhighBehavesLike.Win32.Generic.tt
MalwarebytesVirus.M0yv
VIPREWin32.Expiro.Gen.7
SangforTrojan.Win32.Save.a
K7AntiVirusVirus ( 005a8b911 )
K7GWVirus ( 005a8b911 )
ArcabitWin32.Expiro.Gen.7
SymantecW32.Xpiro.J!dam
ESET-NOD32a variant of Win32/Expiro.NDX
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Moiva.a
BitDefenderWin32.Expiro.Gen.7
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
RisingTrojan.Generic@AI.97 (RDML:WZvQ6Er5VzEPQHGUJvzMFQ)
EmsisoftWin32.Expiro.Gen.7 (B)
F-SecureMalware.W32/Infector.Gen
TrendMicroVirus.Win32.EXPIRO.JMA
SophosW32/Moiva-A
IkarusVirus.Win32.Expiro
GoogleDetected
AviraW32/Infector.Gen
Antiy-AVLVirus/Win32.Expiro.x
MicrosoftVirus:Win32/Expiro.EB!MTB
ZoneAlarmVirus.Win32.Moiva.a
GDataWin32.Expiro.Gen.7
VaristW32/Expiro.AU.gen!Eldorado
Acronissuspicious
VBA32BScope.Worm.MSIL.Agent
ALYacWin32.Expiro.Gen.7
PandaW32/Moyv.A
TencentVirus.Win32.VirMoiva.a
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Expiro.NDP!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove BScope.Worm.MSIL.Agent?

BScope.Worm.MSIL.Agent removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment