Worm

Worm:Win32/Scano malicious file

Malware Removal

The Worm:Win32/Scano is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Scano virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Creates a copy of itself

How to determine Worm:Win32/Scano?


File Info:

name: 514738878E2B947519E4.mlw
path: /opt/CAPEv2/storage/binaries/058caeef2527377dc6ffd7385cc63003267ca3cc7b8495b2bed60c5ab22a2d4d
crc32: 49AA07B8
md5: 514738878e2b947519e491b479449bfe
sha1: 4cdcfeb35c7683ee647ba8a47b43da741b99441c
sha256: 058caeef2527377dc6ffd7385cc63003267ca3cc7b8495b2bed60c5ab22a2d4d
sha512: e7a84803dfa2082e668b68454b1cff0773aa6840a358c7bb50eba1b26baf933c49a9a0568a1820b05b485ebe84fd548d8fd4e090606b2c5e86c0f5c7a1844dcb
ssdeep: 1536:+zCZWH01ZDyXV8hMO8zCzhitUMZ0s8WvnZco0mxydfaSAcnovUYYFQFFlI:wOTDeg8zEitUe15PZcomfaPvUYYCI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10AF36C027BEA8571E5762FB16DE79652C7B9FC22ED66C70F6311720E0E32511CE22722
sha3_384: 8017793425caac0b71edbf41f13bcd80e9d0f0729e92faf725af336dc5fbc618cf2e3bd69062b8669111564d0b714176
ep_bytes: 6803800000e86d0200006a0936a0cc11
timestamp: 1980-09-02 00:47:58

Version Info:

0: [No Data]

Worm:Win32/Scano also known as:

BkavW32.AIDetectMalware.CS
LionicWorm.Win32.Scano.ts1m
DrWebWin32.HLLM.Perf
MicroWorld-eScanGen:Trojan.Malware.jqZ@ayDs0Bk
ClamAVWin.Worm.Scano-9950618-0
FireEyeGeneric.mg.514738878e2b9475
CAT-QuickHealWorm.ScanoCS.S27880409
SkyhighBehavesLike.Win32.Generic.ct
McAfeeGenericRXFW-UY!514738878E2B
Cylanceunsafe
ZillyaWorm.Scano.Win32.613
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 003b1b581 )
AlibabaMalware:Win32/km_28c473.None
K7GWTrojan ( 003b1b581 )
Cybereasonmalicious.35c768
ArcabitTrojan.Malware.EAD1B45
BitDefenderThetaAI:Packer.857CED111D
SymantecW32.Areses.P@mm
Elasticmalicious (high confidence)
ESET-NOD32Win32/Scano.NBL
APEXMalicious
CynetMalicious (score: 100)
KasperskyEmail-Worm.Win32.Scano.bk
BitDefenderGen:Trojan.Malware.jqZ@ayDs0Bk
NANO-AntivirusTrojan.Win32.LdPinch.joxfpy
AvastWin32:Scano-AV [Wrm]
RisingWorm.Mail.Win32.Scano.bk (CLASSIC)
EmsisoftGen:Trojan.Malware.jqZ@ayDs0Bk (B)
F-SecureWorm.WORM/Scano.AR.1
BaiduWin32.Worm.Scano.a
VIPREGen:Trojan.Malware.jqZ@ayDs0Bk
Trapminemalicious.high.ml.score
SophosW32/Scano-I
IkarusEmail-Worm.Win32.Scano
JiangminWorm/Scano.ab
GoogleDetected
AviraWORM/Scano.AR.1
MAXmalware (ai score=84)
Antiy-AVLGrayWare/Win32.Crypt.upack
Kingsoftmalware.kb.a.1000
XcitiumBackdoor.Win32.Popwin.~IT@pe303
MicrosoftWorm:Win32/Scano.gen
ZoneAlarmEmail-Worm.Win32.Scano.bk
GDataGen:Trojan.Malware.jqZ@ayDs0Bk
VaristW32/LdPinch.N.gen!Eldorado
AhnLab-V3Worm/Win.Scano.R487770
Acronissuspicious
VBA32BScope.Trojan-Dropper.Injector
ALYacGen:Trojan.Malware.jqZ@ayDs0Bk
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TencentWorm.Win32.Scano.xa
YandexTrojan.GenAsa!rw4qUFrvLak
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.W32.Packer.Upack0.3.9
FortinetW32/Scano.AA@mm
AVGWin32:Scano-AV [Wrm]
DeepInstinctMALICIOUS

How to remove Worm:Win32/Scano?

Worm:Win32/Scano removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment