Worm

How to remove “BScope.Worm.Socks.afv”?

Malware Removal

The BScope.Worm.Socks.afv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Worm.Socks.afv virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Starts servers listening on 0.0.0.0:15559
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings

How to determine BScope.Worm.Socks.afv?


File Info:

name: 0837B3E85951B5164F4E.mlw
path: /opt/CAPEv2/storage/binaries/408512e14661dfa675603b04859fd343d24fb8ca23e2cc189b316755cb876399
crc32: 620011F3
md5: 0837b3e85951b5164f4ede93fda51c4c
sha1: 4f8f4a6fbb5a1c0cc91d3b641b54883b287b916d
sha256: 408512e14661dfa675603b04859fd343d24fb8ca23e2cc189b316755cb876399
sha512: b9f0a63049e60fac796a199f51da78f8fcd73b430d701cf259413dd44d0358ffad4780e37a6155852e258c4483c8f9866f96d6cf89e3b7512f5fb63b23ab5249
ssdeep: 12288:Cb5syS5Z5Z5sy/yS5Z5Z5Z5B+G5Z5Z5BM5Z5Z5Z5Z5Z5Z5Z5Z5syS5Z5Z5Z5Z5sU:QeaSgmaaaaaa2ab
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12A45024AF5ECAB61E9273CF6E2CD6540847712990E442522F69733A2612ED33D1FD38E
sha3_384: 46ae88db82c325641d4c2d77b2360c4c81815597ae28a496cbc8f5606ccab2ce324d55ae2a5437e26ddbd7579693fe7c
ep_bytes: 60be007057018dbe00a0e8fe5783cdff
timestamp: 2008-04-02 18:32:48

Version Info:

0: [No Data]

BScope.Worm.Socks.afv also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Crypt.AS
FireEyeGeneric.mg.0837b3e85951b516
CAT-QuickHealTrojan.Toga.26592
McAfeeObfuscated-FPR!hb
MalwarebytesMalware.AI.3417656905
ZillyaWorm.Socks.Win32.544
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 0003ef7f1 )
K7GWEmailWorm ( 0003ef7f1 )
Cybereasonmalicious.85951b
VirITTrojan.Win32.Generic.WQH
CyrenW32/Socks.A.gen!Eldorado
SymantecTrojan.Dropper
ESET-NOD32a variant of Win32/Socks.NAJ
APEXMalicious
ClamAVWin.Worm.Socks-7102088-0
KasperskyTrojan-Ransom.Win32.Blocker.jaty
BitDefenderTrojan.Crypt.AS
NANO-AntivirusTrojan.Win32.Socks.crakqx
AvastWin32:Injecter-AT [Trj]
TencentMalware.Win32.Gencirc.10cfe5a7
Ad-AwareTrojan.Crypt.AS
SophosML/PE-A + Troj/Scrub-Gen
DrWebTrojan.KillFiles.13123
VIPREP2P-Worm.Win32.Socks.g (fs)
TrendMicroTROJ_SPNR.30CU14
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftTrojan.Crypt.AS (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Crypt.AS
JiangminTrojan.Blocker.igh
AviraTR/Drop.Agent.snv
Antiy-AVLTrojan/Generic.ASMalwS.183B23A
ArcabitTrojan.Crypt.AS
ZoneAlarmTrojan-Ransom.Win32.Blocker.jaty
MicrosoftTrojan:Script/Phonzy.C!ml
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Socks.R76979
Acronissuspicious
BitDefenderThetaAI:Packer.57E0A16A1B
ALYacTrojan.Crypt.AS
MAXmalware (ai score=86)
VBA32BScope.Worm.Socks.afv
TrendMicro-HouseCallTROJ_SPNR.30CU14
RisingRansom.Blocker!8.12A (RDMK:cmRtazpHJwoAhVIEwXKS6GWwgpEh)
YandexWorm.Socks!kTEylFde0kc
IkarusWorm.Win32.Socks
FortinetW32/Generic.AC.209E!tr
AVGWin32:Injecter-AT [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove BScope.Worm.Socks.afv?

BScope.Worm.Socks.afv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment