Worm

BScope.Worm.Pluto removal

Malware Removal

The BScope.Worm.Pluto is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Worm.Pluto virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine BScope.Worm.Pluto?


File Info:

name: 736BC99C1EE196D4B047.mlw
path: /opt/CAPEv2/storage/binaries/998f5b67cb60acfbf2718831b47bcfda9cd2c8046f5a8425cd108864e1d3b221
crc32: D96A5D5C
md5: 736bc99c1ee196d4b0473dc3c3575507
sha1: a9921d8d1c06c68a33c932bb03595b20fe7c8be1
sha256: 998f5b67cb60acfbf2718831b47bcfda9cd2c8046f5a8425cd108864e1d3b221
sha512: 47343c21f0be2b65be5cf2c36622a6b6c27a46de4f42ba327695279d6e040e8207d8137fc7ab1d7b71de729f1a3887f3e204d6a1aa290ec58714dc52ef4365ba
ssdeep: 1536:zOklqZEg15i1qf5IcxZgXHayKyeZozcnVqwA4DqdJX:S3t17aDafysozcnVqwA4wx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15F04E117F5A0C233C050DAFCDE4FD924D3B73A602E994641BAF52B4F991B6855C2C29E
sha3_384: 1e18b5fb636a7ab36223a321b1db11a5769973dbba1f99317112c550dc62afcca15f6b3252960912df751a8a807be6e8
ep_bytes: 55545d83c4f053b8346f4000e85fd4ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

BScope.Worm.Pluto also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanWorm.P2P.AM
ClamAVWin.Worm.Fearso-7358009-0
FireEyeGeneric.mg.736bc99c1ee196d4
CAT-QuickHealTrojan.IgenericCS.S27288946
ALYacWorm.P2P.AM
CylanceUnsafe
ZillyaWorm.Eggnog.Win32.45121
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.c1ee19
BaiduWin32.Worm.Eggnog.a
CyrenW32/EggNog.H.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Eggnog.E
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Cospet.gen
BitDefenderWorm.P2P.AM
NANO-AntivirusTrojan.Win32.Delphi.iarwcx
AvastWin32:Malware-gen
TencentWorm.Win32.Eggnog.a
Ad-AwareWorm.P2P.AM
EmsisoftWorm.P2P.AM (B)
DrWebWin32.HLLW.Google.24577
VIPREWorm.P2P.AM
McAfee-GW-EditionBehavesLike.Win32.Generic.cz
Trapminemalicious.high.ml.score
SophosTroj/Agent-AJFK
SentinelOneStatic AI – Malicious PE
GDataWin32.Worm.Fearso.A
JiangminTrojan/Cospet.gv
AviraDR/Delphi.Gen
Antiy-AVLTrojan/Generic.ASMalwS.7B8
ZoneAlarmHEUR:Worm.Win32.Generic
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
GoogleDetected
AhnLab-V3Dropper/Win32.Agent.C4331
McAfeePolyPatch-UPX
MAXmalware (ai score=83)
VBA32BScope.Worm.Pluto
MalwarebytesGeneric.Trojan.Malicious.DDS
RisingWorm.Eggnog!1.9A44 (CLASSIC)
YandexTrojan.GenAsa!9WQyNROzKr8
IkarusEmail-Worm.Win32.Fearso
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Eggnog.E!worm
BitDefenderThetaAI:Packer.E009701221
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove BScope.Worm.Pluto?

BScope.Worm.Pluto removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment