Adware

BScope.Adware.MiniPages malicious file

Malware Removal

The BScope.Adware.MiniPages is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Adware.MiniPages virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine BScope.Adware.MiniPages?


File Info:

name: D87E3FD3B2D05223C296.mlw
path: /opt/CAPEv2/storage/binaries/72b419e34926f44418ef232d600d710f6104d66d73505263a3f6f728bc268f6b
crc32: C8CEB010
md5: d87e3fd3b2d05223c29660ddfe977acc
sha1: d284f54eb962599b23b018118445dee8ff3b343c
sha256: 72b419e34926f44418ef232d600d710f6104d66d73505263a3f6f728bc268f6b
sha512: 089d1a29582665a0e2f60630b339a48f22037e46692e2156cd1a91c61bc498b5829f63093e3337d53c6471b4fd2012cb0985a19f93223c55d154b0c981ec0330
ssdeep: 24576:4Ji41uFMHuDNzWRgmHsF5eb99DLZFmggggMCDd9Atk463m2h1t1jTp7tyvO351p:6i4h45Kcg9RwggggMCD/Nnm2/XjTHqO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A3658D20DA41B416F9B3807149EB526C46A8AE305FA450FF97C0E96ADB35DD37A3270F
sha3_384: e48ce6a610289043872f9036e82ac72828bef6f7e68ddbe3912a0d8b243d0b794507585899795a175061d9ef27342900
ep_bytes: e8600c0000e97afeffff558bec5de97e
timestamp: 2020-05-25 03:22:35

Version Info:

CompanyName: 北京小树发芽网络科技有限公司
FileDescription: SmallTreesUpdate.exe
FileVersion: 1.1.2.1
InternalName: SmallTreesUpdate.exe
LegalCopyright: Copyright (C) 2019
OriginalFilename: SmallTreesUpdate.exe
ProductName: SmallTreesUpdate.exe
ProductVersion: 1.1.2.1
Translation: 0x0804 0x04b0

BScope.Adware.MiniPages also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.MiniPages.2!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.d87e3fd3b2d05223
CylanceUnsafe
ZillyaAdware.MiniPages.Win32.256
SangforVirus_Suspicious.Win32.Sality.bh
AlibabaAdWare:Win32/AntZip.9d51a278
K7GWAdware ( 0058a9291 )
K7AntiVirusAdware ( 0058a9291 )
VirITWin32.Sality.BI
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/AntZip.A potentially unwanted
TrendMicro-HouseCallPE_SALITY.ER
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.Win32.MiniPages.gen
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Sality [Inf]
TencentPua:AdWare.Win32.MiniPages.16000084
F-SecureTrojan.TR/Patched.Ren.Gen
VIPREVirus.Win32.Sality.atbh (v)
TrendMicroPE_SALITY.ER
McAfee-GW-EditionBehavesLike.Win32.PUP.th
SentinelOneStatic AI – Malicious PE
SophosGeneric PUA NC (PUA)
APEXMalicious
AviraTR/Patched.Ren.Gen
GridinsoftRansom.Win32.Sabsik.sa
ViRobotAdware.Minipages.1548664
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Adware.MiniPages
MalwarebytesMalware.Heuristic.1001
RisingAdware.Agent!1.C64A (CLASSIC)
YandexPUA.MiniPages!lh1aQiTlHNA
IkarusPUA.AntZip
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/AntZip
AVGWin32:Sality [Inf]

How to remove BScope.Adware.MiniPages?

BScope.Adware.MiniPages removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment