Adware

About “Adware.CandyOpen” infection

Malware Removal

The Adware.CandyOpen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.CandyOpen virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Detects the presence of Wine emulator via registry key
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Creates a copy of itself
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Adware.CandyOpen?


File Info:

name: 52D3E3C14FA2AA0320C7.mlw
path: /opt/CAPEv2/storage/binaries/4a4a1d6d407faf758355a8393713227aa0e39617f2376836125d66f260915eba
crc32: 36F6CE0D
md5: 52d3e3c14fa2aa0320c7e3cf76b455c2
sha1: ac698e6145e14e6ada3002fe06e5d610c1c8a026
sha256: 4a4a1d6d407faf758355a8393713227aa0e39617f2376836125d66f260915eba
sha512: 11a66b48727af2669a211ac3da43752e26c23870169faa0fd3449d1cec43b84cf87a3cbdef1dfd5fe12ecd0c13ddcbac39ef39ed8c81de71c1e2ff2adcf216b9
ssdeep: 24576:1Uv18lc6PJkDSJ0mTI03pAcLA1UqS5Kjkx1LG9JRhPkaq/JnX:1U98lc6aDfm5/yUNfxIRh8aqpX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A76523D6C79D3E95D4CC12B205322B9E6865CC14F9791E331626383F98F22E26D52CAF
sha3_384: e4b8654cb8603ba032f636e426d7ca0fb4340be47c4646c2fa431e96f3c89c46421ba2f8345e0aef24a7021d6fa9cea7
ep_bytes: 60be00b066008dbe0060d9ff5789e58d
timestamp: 2014-09-17 18:00:35

Version Info:

CompanyName: BitTorrent Inc.
FileDescription: µTorrent
FileVersion: 3.4.2.34024
InternalName: uTorrent.exe
OriginalFilename: uTorrent.exe
LegalCopyright: ©2014 BitTorrent, Inc. All Rights Reserved.
ProductName: µTorrent
ProductVersion: 3.4.2.34024
SpecialBuild: stable34 stable
Translation: 0x0409 0x04e4

Adware.CandyOpen also known as:

BkavW32.AIDetectMalware
LionicRiskware.Win32.Generic.1!c
ClamAVWin.Virus.Parite-7090238-0
SangforTrojan.Win32.Agent.Vzgr
K7AntiVirusAdware ( 0055f4f21 )
K7GWAdware ( 0055f4f21 )
CrowdStrikewin/grayware_confidence_100% (D)
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/uTorrent.C potentially unwanted
APEXMalicious
Trapminemalicious.moderate.ml.score
SophosGeneric Reputation PUA (PUA)
IkarusPUA.Conduit
GDataWin32.Application.OpenCandy.R
JiangminTrojan.Generic.gbwa
GoogleDetected
VBA32Adware.CandyOpen
Cylanceunsafe
RisingTrojan.Win32.Generic.180D7D23 (C64:YzY0OrwofjFbPpxm)
YandexTrojan.GenAsa!QHzLgOpUb80
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/BitTorrent.PUP
DeepInstinctMALICIOUS

How to remove Adware.CandyOpen?

Adware.CandyOpen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment