Adware

Should I remove “BScope.Adware.Wews”?

Malware Removal

The BScope.Adware.Wews is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Adware.Wews virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
a.clickdata.37wan.com

How to determine BScope.Adware.Wews?


File Info:

crc32: ACD0A34A
md5: 51b5403acaf3eaa227989df2eb43a4ee
name: msgbb_1210.exe
sha1: a7f6f0664e40e80ff09be22a7bde070c26cd52d9
sha256: 2a0206a25fa571b754690ba79b4873e311fc7079ec26215036dd16fb6e79cf6d
sha512: 4742665ca5aa7d0d39f520493fd361572cc1627b5de743050c64183d06288f34f9faf95de9a962ef8ca7a40c016af88d2b1c8397d6b64cb046595dd05a0d5427
ssdeep: 24576:m7wFBwLVL8RjmPyMAmjoo+WOFzaV+6zR2aaPV5ikQRb6Fj4A:mUFCNbAKookw+c2NNL
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: x4e0ax6d77x4e09x4e03x73a9x7f51x7edcx79d1x6280x6709x9650x516cx53f8
FileVersion: 3.0.0.0
CompanyName: x4e0ax6d77x4e09x4e03x73a9x7f51x7edcx79d1x6280x6709x9650x516cx53f8
ProductName: x706dx795exff1ax9ad8x7206x7248
ProductVersion: 3.0.0.0
FileDescription: x706dx795exff1ax9ad8x7206x7248 install
Translation: 0x0804 0x03a8

BScope.Adware.Wews also known as:

FireEyeGeneric.mg.51b5403acaf3eaa2
CAT-QuickHealApplication.Agent.ZZ5
Qihoo-360Win32/Virus.Adware.b51
McAfeeArtemis!51B5403ACAF3
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 004fef751 )
K7GWAdware ( 004fef751 )
CrowdStrikewin/malicious_confidence_60% (D)
Invinceaheuristic
SymantecSMG.Heur!gen
APEXMalicious
AvastWin32:PUP-gen [PUP]
GDataWin32.Application.Agent.U27VPB
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
AlibabaAdWare:Win32/Wews87.ebdc79cb
Endgamemalicious (high confidence)
SophosGeneric PUA KH (PUA)
ComodoApplication.Win32.Wews87.E@7mby71
F-SecureAdware.ADWARE/Wews87.wojiq
DrWebProgram.Unwanted.3980
TrendMicroTROJ_GEN.R002C0OB220
McAfee-GW-EditionArtemis
IkarusAdWare.Wews87
CyrenW32/Application.OPGV-8536
AviraADWARE/Wews87.wojiq
MAXmalware (ai score=99)
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Generic
MicrosoftProgram:Win32/Uwasson.A!ml
AhnLab-V3Malware/Gen.Generic.C3979729
VBA32BScope.Adware.Wews
MalwarebytesAdware.ChinAd
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Wews87.B potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0OB220
RisingPUA.Wews87!8.642 (CLOUD)
eGambitUnsafe.AI_Score_74%
FortinetRiskware/Wews87
AVGWin32:PUP-gen [PUP]

How to remove BScope.Adware.Wews?

BScope.Adware.Wews removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment