Adware

BScope.Adware.Amonetize removal instruction

Malware Removal

The BScope.Adware.Amonetize is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Adware.Amonetize virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine BScope.Adware.Amonetize?


File Info:

name: 652AA8F626FAECFC4753.mlw
path: /opt/CAPEv2/storage/binaries/cb408e4783703f225c669ede0ae4b58c0bdfff2fa9930d7d8fca14830c14e62d
crc32: 3D4FEBA2
md5: 652aa8f626faecfc4753641645a85280
sha1: 0a20cb12a70f8bb10f14ff4e38d72b7ba3bb38d0
sha256: cb408e4783703f225c669ede0ae4b58c0bdfff2fa9930d7d8fca14830c14e62d
sha512: 57bbbee5752a85cdce4d4325d89622878dbae76db2a337deabf5a67a389738975d4871b39dd1299afbe7c438c16010c77d81c2459b9063e09eb3973894838671
ssdeep: 24576:9u4WW0dAkemn6aEL8wRC+iETKB+XOKFx4V2n0bK7:9u00Y7iES+X2Vy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C1552B137232DCA1E4151B7681A6933867389E087075C527F7ECAD63FFB9A125B0E70A
sha3_384: 5a76cbd9d5d7dcb75916194ca9948b3759b9e74e9b1f5efd4c8629bd0f99511c0955a88a625e75f43433ed350796a76f
ep_bytes: e86b4c0800e8a63e080033c0c3909090
timestamp: 2016-10-28 14:49:17

Version Info:

FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
CompanyName: GBT游戏小组
FileDescription: GAME_SETUP_ALL
InternalName: GBT_Setup
LegalCopyright: GBT游戏小组版权所有,游戏原厂商所有,仅作为作品交流
LegalTrademarks: China
OriginalFilename: Setup
ProductName: GBT Setup
GBT游戏小组: 790439046
Translation: 0xffff 0x0000

BScope.Adware.Amonetize also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.652aa8f626faecfc
McAfeeGenericRXCZ-XT!652AA8F626FA
CylanceUnsafe
Cybereasonmalicious.626fae
BitDefenderThetaGen:NN.ZexaF.34182.qr0aa0I2MRcb
CyrenW32/BlackMoon.J.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FlyStudio.Injector.A potentially unwanted
Paloaltogeneric.ml
ClamAVWin.Dropper.Tiggre-9845940-0
NANO-AntivirusTrojan.Win32.FlyStudio.fyogfx
AvastWin32:Malware-gen
APEXMalicious
Antiy-AVLTrojan/Generic.ASCommon.218
MicrosoftTrojan:Win32/Wacatac.B!ml
VBA32BScope.Adware.Amonetize
RisingTrojan.Kryptik!1.B3E8 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.12255096.susgen
FortinetW32/Agent.WP!tr
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove BScope.Adware.Amonetize?

BScope.Adware.Amonetize removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment