Adware

BScope.Adware.Wajam removal guide

Malware Removal

The BScope.Adware.Wajam is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Adware.Wajam virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Accessed credential storage registry keys
  • Created a service that was not started
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine BScope.Adware.Wajam?


File Info:

name: 07F8420BC941BE8A6CCC.mlw
path: /opt/CAPEv2/storage/binaries/6567cfc47092a86491336fb79f74615050d5a5c203ffa49ecf02c95085411ba7
crc32: E6FB0B2E
md5: 07f8420bc941be8a6ccc304ae04d3f4c
sha1: ff882dc36badce763f47430f5660b8a8627f039f
sha256: 6567cfc47092a86491336fb79f74615050d5a5c203ffa49ecf02c95085411ba7
sha512: fe6c20f11c801e0d186ce40bc4e3ac365d148ab17323fea014d47a6df55d9e577eb44de9709ff3a44b57f45e8bdb3a415c95c5dfd42eabd98ef70e2f8ac749f2
ssdeep: 196608:1ih9aaGci167yhRV8ACU1kX6dezNn5jvPrQzUwmyuosA3smD:1ihQ3eSRV8Ad9ezJ1MUv+sAc+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T155963358A7E8D9E7EC9F90F2413C83889A3EED6235AA8A0BD5C0359735735914C8F743
sha3_384: e5ddec3df4c78fefa59deebb5a9c46726dd931c0c63dec8df8b6ccb360963b6a63dfed55519b9522feaf6d4a965a0671
ep_bytes: 81ecd4020000535556576a2033ed5e89
timestamp: 2010-08-20 13:21:38

Version Info:

0: [No Data]

BScope.Adware.Wajam also known as:

LionicTrojan.Win32.Adload.4!c
Elasticmalicious (high confidence)
DrWebAdware.Wajam.932
MicroWorld-eScanTrojan.GenericKD.40731379
FireEyeGeneric.mg.07f8420bc941be8a
McAfeeArtemis!07F8420BC941
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.220018
SangforTrojan.Win32.GenericKD.4
K7AntiVirusAdware ( 00544e2e1 )
AlibabaAdWare:Win32/AdLoad.52de0fcf
K7GWAdware ( 00544e2e1 )
Cybereasonmalicious.bc941b
CyrenW32/Adware.FEYA-0692
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
TrendMicro-HouseCallTROJ_FRS.0NA103LB18
KasperskyHEUR:Trojan-Downloader.Win32.Adload.gen
BitDefenderTrojan.GenericKD.40731379
NANO-AntivirusRiskware.Win32.Zdengo.fjxwux
AvastWin32:Adware-gen [Adw]
Ad-AwareTrojan.GenericKD.40731379
EmsisoftTrojan.GenericKD.40731379 (B)
ComodoApplicUnwnt@#uuhkr00e40z7
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_FRS.0NA103LB18
McAfee-GW-EditionBehavesLike.Win32.PUPXBT.rc
SophosMal/Generic-S
GDataTrojan.GenericKD.40731379
AviraTR/AD.Zdengo.ciszu
Antiy-AVLTrojan/Generic.ASMalwS.346B0F2
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ArcabitTrojan.Generic.D26D82F3
MicrosoftTrojan:Win32/Sabsik!ml
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.Wajam.R260046
VBA32BScope.Adware.Wajam
ALYacTrojan.GenericKD.40731379
MalwarebytesAdware.Zdengo
APEXMalicious
RisingTrojan.Bitrep!8.F596 (CLOUD)
YandexPUA.Zdengo!Z1OQnf2zS+4
eGambitUnsafe.AI_Score_78%
WebrootW32.Adware.Installcore
AVGWin32:Adware-gen [Adw]
PandaTrj/CI.A
CrowdStrikewin/grayware_confidence_100% (D)

How to remove BScope.Adware.Wajam?

BScope.Adware.Wajam removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment