Adware

Adware.Agent.Generic removal guide

Malware Removal

The Adware.Agent.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Agent.Generic virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Anomalous binary characteristics

Related domains:

goodthingshostedhere.com

How to determine Adware.Agent.Generic?


File Info:

crc32: 27808EDD
md5: 17cea0a80a61deaba0704ac0362c0dcc
name: 17CEA0A80A61DEABA0704AC0362C0DCC.mlw
sha1: eaa11bd02e1ca4066892be554444ed5716b7f501
sha256: f8aafafc344620c8d35ff51407ca809721f7ce949abeef19ee8e26dfdb761bfe
sha512: f2e2df6149e36c9cf8c0b3023fbe85cd536f18114bbab4290d62aba5bc16282f117a65ed28fe05af8a7986bce5f1d19799f5543fa559773ed29e45081ba94a51
ssdeep: 192:ynxt2ikuo9qcL8BMEamYBAW+TofN+5+8m+Q+Pm+9++m+WfN+gOjpcS:yHnkzoBMEam8XZVoChjE0fVhOjK
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2017
Assembly Version: 1.0.0.0
InternalName: HappyOmek.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: AdsShow_installer
ProductVersion: 1.0.0.0
FileDescription: AdsShow_installer
OriginalFilename: HappyOmek.exe

Adware.Agent.Generic also known as:

MicroWorld-eScanTrojan.GenericKD.4866631
Qihoo-360Win32/RootKit.Rootkit.7e5
McAfeeArtemis!17CEA0A80A61
CylanceUnsafe
ZillyaDownloader.Agent.Win32.333820
SangforMalware
K7AntiVirusTrojan-Downloader ( 0050c5601 )
BitDefenderTrojan.GenericKD.4866631
K7GWTrojan-Downloader ( 0050c5601 )
Cybereasonmalicious.80a61d
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
KasperskyUDS:DangerousObject.Multi.Generic
NANO-AntivirusTrojan.Win32.GenericKD.eoucic
AegisLabTrojan.Multi.Generic.4!c
RisingMalware.Undefined!8.C (CLOUD)
Ad-AwareTrojan.GenericKD.4866631
EmsisoftTrojan.GenericKD.4866631 (B)
ComodoMalware@#qom668rwmvk1
F-SecureHeuristic.HEUR/AGEN.1130474
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_DLOADER.SMIL
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.17cea0a80a61deab
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.GenKD
AviraHEUR/AGEN.1130474
MAXmalware (ai score=99)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D4A4247
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataTrojan.GenericKD.4866631
CynetMalicious (score: 85)
BitDefenderThetaGen:NN.ZemsilF.34804.am0@ae1n3Fh
ALYacTrojan.GenericKD.4866631
MalwarebytesAdware.Agent.Generic
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.DIV
TrendMicro-HouseCallTROJ_DLOADER.SMIL
TencentMsil.Trojan-downloader.Agent.Eaeg
YandexTrojan.Agent!iFTCyiIcUSo
IkarusTrojan-Downloader.Win32.Agent
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Generic.AP.7CBF1E!tr
AVGWin32:Rootkit-gen [Rtk]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Adware.Agent.Generic?

Adware.Agent.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment