Categories: Adware

About “BScope.Adware.Agent” infection

The BScope.Adware.Agent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Adware.Agent virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity contains more than one unique useragent.

Related domains:

www.ezkeyqq.com
www.time.ac.cn

How to determine BScope.Adware.Agent?


File Info:

crc32: 44705C88md5: 9052357e1e0ad8480a6e8f8b28a38e9ename: menghuanxiyoudatu.exesha1: 16ac128302def7a32b4ddc5a6e28b306e2b20ce2sha256: f21fb8cc87daca69018219ccacf9fedc062a35326612b6512f4d14986f25a5b6sha512: 89e1d14bb17a63860e8085e580b9339177a76aa4440b998534ddb4fdf5118d9334dfc51bfe68aefcb2f8c525d5b34a473da3fa0cdb5415441507c9af707e5cafssdeep: 49152:1hqDqm5rdBbSiLM9lG4Oq7IXTIGQ1UWCsVb6KUpZ+hDg1F2d6N63:XqDqm5JtSyM9lG4Ow1U5SbWf+YFCdtype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x4f5cx8005x7248x6743x6240x6709 x8bf7x5c0ax91cdx5e76x4f7fx7528x6b63x7248FileVersion: 3.3.1.23Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.eyuyan.com)ProductName: x6613x8bedx8a00x7a0bx5e8fProductVersion: 3.3.1.23FileDescription: x6613x8bedx8a00x7a0bx5e8fTranslation: 0x0804 0x04b0

BScope.Adware.Agent also known as:

Bkav W32.AIDetectVM.malware
MicroWorld-eScan Trojan.GenericKD.31291129
FireEye Generic.mg.9052357e1e0ad848
Qihoo-360 Win32/Trojan.4c6
McAfee GenericRXBO-IQ!9052357E1E0A
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
AegisLab Trojan.Multi.Generic.4!c
K7AntiVirus Riskware ( 0040eff71 )
BitDefender Trojan.GenericKD.31291129
K7GW Riskware ( 0040eff71 )
Cybereason malicious.e1e0ad
Invincea heuristic
Cyren W32/Agent.EW.gen!Eldorado
Symantec ML.Attribute.HighConfidence
APEX Malicious
Avast Win32:Malware-gen
ClamAV Win.Trojan.Kazy-6878
GData Win32.Application.PUPStudio.A
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba RiskWare:Win32/IMEStartup.6f694b66
NANO-Antivirus Trojan.Win32.Chistudi.cvlvfb
ViRobot Trojan.Win32.Z.Chistudi.3100672
Tencent Win32.Trojan.Agent.Mgen
Endgame malicious (high confidence)
Sophos Mal/Generic-S
Comodo TrojWare.Win32.Agent.OSCF@5rs7jr
F-Secure Trojan:W32/DelfInject.R
DrWeb Trojan.PWS.Wsgame.35243
Zillya Trojan.Chistudi.Win32.19
TrendMicro TROJ_GEN.R002C0OBI20
McAfee-GW-Edition BehavesLike.Win32.Generic.vc
Emsisoft Trojan.GenericKD.31291129 (B)
Ikarus Trojan.Crypt
F-Prot W32/Agent.EW.gen!Eldorado
Jiangmin Trojan/Chistudi.y
Webroot W32.Chistudi
Avira TR/Agent.3100672.29
Antiy-AVL Trojan/Win32.Chistudi
Arcabit Trojan.Generic.D1DD76F9
ZoneAlarm not-a-virus:RiskTool.Win32.IMEStartup.wpk
Microsoft VirTool:WinNT/Rootkitdrv
TACHYON Trojan/W32.Chistudi.3100672
AhnLab-V3 Trojan/Win32.Chistudi.C1784974
Acronis suspicious
VBA32 BScope.Adware.Agent
ALYac Trojan.GenericKD.31291129
MAX malware (ai score=100)
Ad-Aware Trojan.GenericKD.31291129
Panda Generic Malware
ESET-NOD32 a variant of Win32/Packed.FlyStudio.AA potentially unwanted
TrendMicro-HouseCall TROJ_GEN.R002C0OBI20
Rising Trojan.Chistudi!8.1DB9 (CLOUD)
Yandex Trojan.Chistudi!MR4nt8wRd+4
SentinelOne DFI – Malicious PE
eGambit HackTool.Generic
Fortinet W32/Chistudi.SA!tr
BitDefenderTheta Gen:NN.ZexaF.34106.9s0@aOjhimgb
AVG Win32:Malware-gen
Paloalto generic.ml
CrowdStrike win/malicious_confidence_90% (W)
MaxSecure Trojan.Malware.8138342.susgen

How to remove BScope.Adware.Agent?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

Should I remove “Trojan.GenericFCA.Agent.31999”?

The Trojan.GenericFCA.Agent.31999 is considered dangerous by lots of security experts. When this infection is active,…

3 mins ago

Virus.Win32.Muce.a information

The Virus.Win32.Muce.a is considered dangerous by lots of security experts. When this infection is active,…

8 mins ago

Worm.Autorun.NC3 removal

The Worm.Autorun.NC3 is considered dangerous by lots of security experts. When this infection is active,…

8 mins ago

Should I remove “Worm.Win32.Vobfus.effh”?

The Worm.Win32.Vobfus.effh is considered dangerous by lots of security experts. When this infection is active,…

14 mins ago

Should I remove “Zusy.546276”?

The Zusy.546276 is considered dangerous by lots of security experts. When this infection is active,…

28 mins ago

Toggle Download Manager (PUA) removal instruction

The Toggle Download Manager (PUA) is considered dangerous by lots of security experts. When this…

29 mins ago