Adware

Should I remove “BScope.Adware.Machaer”?

Malware Removal

The BScope.Adware.Machaer is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Adware.Machaer virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine BScope.Adware.Machaer?


File Info:

name: 9B312888485327442A54.mlw
path: /opt/CAPEv2/storage/binaries/02ce7dff45b5a4706351c3fc5d7eb74e769714ffb78fb1861579eaaf47d3704c
crc32: D17C570B
md5: 9b312888485327442a54fdde7f55d2d8
sha1: 10d1724509a050c7895f81b5214a6a5355ec44a0
sha256: 02ce7dff45b5a4706351c3fc5d7eb74e769714ffb78fb1861579eaaf47d3704c
sha512: 35b34db17df942545d3845a6240c1fb21ac232d9caeda9cf43ac3dc87ef5f08ba83fe5fadd2b2ab64a3216b0d4d571a5e6c55a78631999adae80104c7376cb26
ssdeep: 3072:+5ERKdsNSE8jWf+FnGevgjFA+WzmLpJhJ4RpS:+wB8qonGeoFA0lyp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15E047D1136D0C0B1D6B3023609E9AB71A6BDFD714F618B5B77984B4D1EB42C0BA36B63
sha3_384: 19d057d748a605c4d39760a76419e25dc7cf0f96b49960c77b55cda5a831e8eb44863bbf23437c15dbe4a7e43a4a63cd
ep_bytes: e83c720000e97ffeffff558bec8b4508
timestamp: 2018-04-02 14:25:18

Version Info:

CompanyName: Mail.Ru
FileDescription: Mail.Ru Launcher
FileVersion: 3.15.0.75
InternalName: launcher
LegalCopyright: Copyright 2015
OriginalFilename: launcher.exe
ProductName: Mail.Ru Launcher
ProductVersion: 3.15.0.75
Comments:
Translation: 0x0409 0x04b0

BScope.Adware.Machaer also known as:

LionicAdware.Win32.Machaer.2!c
Elasticmalicious (high confidence)
DrWebTrojan.Revizer.1409
MicroWorld-eScanTrojan.GenericKDZ.74312
FireEyeGeneric.mg.9b31288848532744
CAT-QuickHealPUA.LoadmoneyPMF.S19249780
McAfeePUP-HAI
ZillyaTool.Agent.Win32.26977
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 005170991 )
AlibabaAdWare:Win32/MailRu.3f0bee03
K7GWAdware ( 005170991 )
Cybereasonmalicious.848532
CyrenW32/S-2773094c!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/MailRu.R potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0OKR21
ClamAVWin.Malware.Mailru-6804164-0
Kasperskynot-a-virus:HEUR:AdWare.Win32.Machaer.gen
BitDefenderTrojan.GenericKDZ.74312
SUPERAntiSpywarePUP.Downloader/Variant
AvastWin32:PUP-gen [PUP]
Ad-AwareTrojan.GenericKDZ.74312
SophosMail.ru Downloader (PUA)
ComodoApplication.Win32.MailRu.M@7oho6u
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0OKR21
McAfee-GW-EditionBehavesLike.Win32.Downloader.ch
EmsisoftApplication.Downloader (A)
IkarusPUA.MailRu
GDataTrojan.GenericKDZ.74312
JiangminAdWare.Machaer.ad
eGambitUnsafe.AI_Score_99%
AviraAPPL/MailRu.B
Antiy-AVLTrojan/Generic.ASBOL.C4F7
ViRobotTrojan.Win32.Mailru.Gen.B
MicrosoftPUAAdvertising:Win32/LoadMoney
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.MailRu.R232581
VBA32BScope.Adware.Machaer
ALYacTrojan.GenericKDZ.74312
MAXmalware (ai score=84)
MalwarebytesRiskWare.Agent
APEXMalicious
YandexTrojan.GenAsa!jAEP24k3Yx8
SentinelOneStatic AI – Malicious PE
MaxSecureAdware.Adware.Machaer.gen_172020
FortinetW32/MailRu.M!tr
AVGWin32:PUP-gen [PUP]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove BScope.Adware.Machaer?

BScope.Adware.Machaer removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment