Adware

What is “Adware.ConvertAd.1094”?

Malware Removal

The Adware.ConvertAd.1094 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.ConvertAd.1094 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

duckduckgo.com
2.derstannwww.net
4.derstannwww.net
3.derstannwww.net
1.derstannwww.net

How to determine Adware.ConvertAd.1094?


File Info:

crc32: A73541D7
md5: a4d21ba04c59e7147956bd3a32a7a4dd
name: A4D21BA04C59E7147956BD3A32A7A4DD.mlw
sha1: 95eb55981962a2746b496d139cdc997bd97377cb
sha256: e89b228ecbaa81a83a9e2f10ab90bfbab517645a8590f43a02bfd08f0b62db01
sha512: e41c24742cedc20cca2e7fe3601132faae6beb100ed561a9a90d7f8868c50a34424e178e57830408ae5c3bf4133ac32a781793877ae0eec867ada7b8fd92ccde
ssdeep: 3072:vtwLDLwZ2PZV/jONrDxRxbXdXLU1Ru2X6+BCCiddUrqyj7KLWxJ/OLZ:1wHzOt97p7a8OCTS9E
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Adware.ConvertAd.1094 also known as:

BkavW32.FamVT.RazyNHmA.Trojan
K7AntiVirusTrojan ( 004f4dce1 )
LionicTrojan.Win32.Upatre.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.ConvertAd.1094
ALYacGen:Variant.Adware.ConvertAd.1094
CylanceUnsafe
ZillyaDownloader.Upatre.Win32.69368
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanDownloader:Win32/Upatre.012bd9a1
K7GWTrojan ( 004f4dce1 )
Cybereasonmalicious.04c59e
BaiduWin32.Trojan.Kryptik.avl
CyrenW32/S-125f0b2e!Eldorado
SymantecPacked.Generic.521
ESET-NOD32a variant of Win32/Kryptik.FBGA
APEXMalicious
AvastWin32:Adware-gen [Adw]
CynetMalicious (score: 100)
BitDefenderGen:Variant.Adware.ConvertAd.1094
NANO-AntivirusTrojan.Win32.Kryptik.evgvdy
TencentWin32.Trojan-downloader.Upatre.Lnxq
Ad-AwareGen:Variant.Adware.ConvertAd.1094
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanDownloader.Wauchos.BC@6psy7h
BitDefenderThetaAI:Packer.B52B985C21
VIPRETrojan.Win32.Generic!BT
TrendMicroWORM_HPKASIDET.SM0
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
FireEyeGeneric.mg.a4d21ba04c59e714
EmsisoftGen:Variant.Adware.ConvertAd.1094 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.tldnh
Antiy-AVLTrojan/Generic.ASMalwS.22C16F7
MicrosoftVirTool:Win32/CeeInject
GDataGen:Variant.Adware.ConvertAd.1094
AhnLab-V3Trojan/Win32.Zbot.R133369
McAfeeRDN/Generic Downloader.x
MAXmalware (ai score=100)
VBA32BScope.Trojan.Kasidet
PandaTrj/GdSda.A
TrendMicro-HouseCallWORM_HPKASIDET.SM0
RisingTrojan.Generic@ML.90 (RDML:ov7ME+1kQDRQNBpGE1BPyg)
YandexTrojan.DL.Upatre!RfO5tva1ZLo
IkarusTrojan-Downloader.Win32.Wauchos
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.FAPE!tr
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Adware.ConvertAd.1094?

Adware.ConvertAd.1094 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment