Adware

BScope.Adware.Pokavampo information

Malware Removal

The BScope.Adware.Pokavampo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Adware.Pokavampo virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine BScope.Adware.Pokavampo?


File Info:

name: 132EA41F7E7B9B658871.mlw
path: /opt/CAPEv2/storage/binaries/7fb560083c04c0aff162c9c6fe7c4854185a9e37e7d3bd75a3a8146a886421a9
crc32: 11FA495E
md5: 132ea41f7e7b9b658871406d46a7c343
sha1: 9df7c6dfe0024437e385099704995d783c792263
sha256: 7fb560083c04c0aff162c9c6fe7c4854185a9e37e7d3bd75a3a8146a886421a9
sha512: b89e91bc1d1f28dae4b05df2f13a6a6d5a5c56c3fb2649c34669889ddbfd549ef458a9020f403bb84a608a6c16d1840bdf3e6c915ef2847213acd0e334ab2aa7
ssdeep: 1536:e/kGTayWPHdjw6AvJ4G2AHK6vGqagDKmohTtn4K2ku9Ub+x:wTarwPEAtaSKmYY9Ub+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T172A3AF3270E0C072C19724358D65EAB26ABEF4321B708A8B779C167D5FA07D1DB29397
sha3_384: 0f52f58ef2e3ca979fe51c93cb028b56d7fec975afea7473797454c463c6caf5f462e6117ebbbdcded0d7ee795aba315
ep_bytes: e81a4e0000e989feffff8bff558bec83
timestamp: 2015-09-16 14:20:52

Version Info:

0: [No Data]

BScope.Adware.Pokavampo also known as:

LionicTrojan.Win32.Zbot.mAzp
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.ConvertAd.125
ALYacGen:Variant.Adware.ConvertAd.125
CylanceUnsafe
VIPREGen:Variant.Adware.ConvertAd.125
SangforTrojan.Win32.Save.a
BitDefenderGen:Variant.Adware.ConvertAd.125
CrowdStrikewin/grayware_confidence_100% (D)
ArcabitTrojan.Adware.ConvertAd.125
VirITTrojan.Win32.Agent5.AFQY
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.ConvertAd.ZM
APEXMalicious
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
AlibabaAdWare:Win32/ConvertAd.2fd541aa
NANO-AntivirusRiskware.Win32.ConvertAd.dxnvda
RisingTrojan.Generic@AI.100 (RDML:7IEfsK7KNsg320N6zqSKuA)
Ad-AwareGen:Variant.Adware.ConvertAd.125
SophosGeneric ML PUA (PUA)
ComodoApplicUnwnt@#astqmeu7qgcq
DrWebAdware.ClickMeIn.3474
ZillyaAdware.ConvertAD.Win32.11897
McAfee-GW-EditionBehavesLike.Win32.PUP.nh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.132ea41f7e7b9b65
EmsisoftGen:Variant.Adware.ConvertAd.125 (B)
IkarusPUA.ConvertAd
JiangminAdWare.Generic.aakv
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1224231
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.36B9
MicrosoftPUABundler:Win32/Pokavampo
GDataGen:Variant.Adware.ConvertAd.125
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.ConvertAd.C1008666
McAfeeArtemis!132EA41F7E7B
VBA32BScope.Adware.Pokavampo
PandaTrj/Genetic.gen
TencentMalware.Win32.Gencirc.114c64dd
YandexTrojan.GenAsa!ovm9I868YBA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/ConvertAd
BitDefenderThetaGen:NN.ZexaCO.34806.gqW@aGrkND
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.f7e7b9
AvastWin32:Adware-gen [Adw]

How to remove BScope.Adware.Pokavampo?

BScope.Adware.Pokavampo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment