Adware

BScope.Adware.Weiduan removal

Malware Removal

The BScope.Adware.Weiduan is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Adware.Weiduan virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine BScope.Adware.Weiduan?


File Info:

crc32: B3B3A9DA
md5: acc3dbe506e7f1cee008b64fedc9ea2b
name: 501_20160628.exe
sha1: 99881dda5d2bb71c1b99dcb7a580d5e1fe2776f4
sha256: 8dbf8fb66e6187f0d41a98005fec3b2509abfef8ad0f6b14e1c500b1a9fc783c
sha512: d5f995d6bb4ab62c9cf6853da139dde2a6b106a4a157e0de6ced1361ab2d07c5daa34154dfb21dbe0054065c5c049abbf06fcd77a8edf762febd9f5ae406569d
ssdeep: 24576:M3yTaikK/B08IgG4dg+F1E8pK8mXpyIygZ4aXq2WYIftyrqSEsonmiUnD+:MNikKJbjG4dJypyKXjWDY2SEonD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2015
InternalName: install.exe
FileVersion: 1.0.0.0
CompanyName: x5317x4eacx4e91x7acbx65b9x79d1x6280x6709x9650x516cx53f8
ProductName: wifi
ProductVersion: 1.0.0.0
FileDescription: x4e3bx9898x5b89x88c5x7a0bx5e8f
OriginalFilename: install.exe
Translation: 0x0804 0x04b0

BScope.Adware.Weiduan also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.32370994
FireEyeGeneric.mg.acc3dbe506e7f1ce
McAfeeArtemis!ACC3DBE506E7
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 004dbb9d1 )
BitDefenderTrojan.GenericKD.32370994
K7GWAdware ( 004dbb9d1 )
APEXMalicious
AvastWin32:Adware-gen [Adw]
GDataTrojan.GenericKD.32370994
NANO-AntivirusRiskware.Win32.Weiduan.ebntag
ViRobotAdware.Weiduan.1798656
AegisLabTrojan.Win32.Generic.4!c
TencentMalware.Win32.Gencirc.10b3e9dd
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.32370994 (B)
F-SecureHeuristic.HEUR/AGEN.1019060
DrWebAdware.Weiduan.5
ZillyaAdware.Weiduan.Win32.83
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
MaxSecureTrojan.Malware.9574626.susgen
Trapminesuspicious.low.ml.score
SophosGeneric PUA JJ (PUA)
IkarusPUA.Weiduan
AviraHEUR/AGEN.1019060
Antiy-AVLTrojan/Win32.BTSGeneric
MicrosoftTrojan:Win32/Wacatac.C!ml
ArcabitTrojan.Generic.D1EDF132
VBA32BScope.Adware.Weiduan
ALYacTrojan.GenericKD.32370994
Ad-AwareTrojan.GenericKD.32370994
MalwarebytesAdware.Weiduan
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Adware.Weiduan.G
RisingTrojan.Bitrep!8.F596 (CLOUD)
YandexPUA.Weiduan!
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_50%
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)

How to remove BScope.Adware.Weiduan?

BScope.Adware.Weiduan removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment