Adware

How to remove “BScope.Adware.WatchMan”?

Malware Removal

The BScope.Adware.WatchMan is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Adware.WatchMan virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Transacted Hollowing
  • Collects information about installed applications
  • Creates a hidden or system file
  • Attempts to modify proxy settings

How to determine BScope.Adware.WatchMan?


File Info:

name: 41043CD443B87F55A976.mlw
path: /opt/CAPEv2/storage/binaries/8d5878393252ab6ef7a4f5f7edd71ada1abd1ef1573e521c27d7a7fa0d9d0ea7
crc32: 87B28FBA
md5: 41043cd443b87f55a9769ce63075bff4
sha1: 71fc12c23c0cac7db3a3cf42f2d912f310e933cc
sha256: 8d5878393252ab6ef7a4f5f7edd71ada1abd1ef1573e521c27d7a7fa0d9d0ea7
sha512: 10d65dc1768109b0fc6daf3452999d0a77222affe8dcecd1625f4b4c4bcbd876265d020523946d459e2006cc71ac5a5fa5530ef0be799000f75304de0ae53bc6
ssdeep: 24576:/XBHpvGeDCsTJmyNSZW+WAbC2aNlAG7AxPnFGAClSBBncyQ9ETfKLB6:xpvGejmyNgW+WA2tNlAG7GtGSqb9uq6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12E45334BF2D195EBC12127371D33E07BE13DE3A494029D66AF7017EB625A83B7648AC4
sha3_384: 06e2c1da6c8171d6de846b45b48fa5df3946a9d560fca673d153f17ed9f01baea23fe440fa8585e75334181995bf939d
ep_bytes: 81ec8401000053555633db57895c2418
timestamp: 2014-05-11 20:03:36

Version Info:

FileVersion: 1.3.4.222
ProductVersion: 1.3.4.222
Translation: 0x0409 0x04e4

BScope.Adware.WatchMan also known as:

LionicRiskware.Win32.Malicious.1!c
Elasticmalicious (high confidence)
DrWebAdware.Downware.6419
FireEyeGeneric.mg.41043cd443b87f55
McAfeeArtemis!41043CD443B8
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AlibabaAdWare:Win32/SpeedBit.e792511d
Cybereasonmalicious.23c0ca
ArcabitPUP.Adware.Shopro
ESET-NOD32a variant of Win32/SpeedBit.G potentially unwanted
Paloaltogeneric.ml
NANO-AntivirusRiskware.Nsis.Adw.dtckjs
AvastWin32:Adware-gen [Adw]
McAfee-GW-EditionBehavesLike.Win32.AdwareAdload.tc
SophosGeneric PUA HB (PUA)
AviraADWARE/Adware.Gen
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftProgram:Win32/Wacapew.C!ml
GDataNSIS.Application.Crypted.C
CynetMalicious (score: 100)
VBA32BScope.Adware.WatchMan
APEXMalicious
SentinelOneStatic AI – Malicious PE
AVGWin32:Adware-gen [Adw]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove BScope.Adware.WatchMan?

BScope.Adware.WatchMan removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment