Categories: Adware

About “Adware.ConvertAd.134” infection

The Adware.ConvertAd.134 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.ConvertAd.134 virus can do?

  • Mimics the system’s user agent string for its own requests
  • Network anomalies occured during the analysis.
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Deletes its original binary from disk
  • Attempts to modify proxy settings
  • Creates a copy of itself

How to determine Adware.ConvertAd.134?


File Info:

crc32: 027331D6md5: 4b3664bb61f9444e801ef82ad788fa1aname: 4B3664BB61F9444E801EF82AD788FA1A.mlwsha1: 3d2ecfa001ed14fa2fde0a2d40e8448a804f493csha256: 793a4b8a48089a785e2be95a55655ea5530b1e752d6409720d10effc1278efadsha512: 315df2d09c683f202c351a6bbe17a4c8c12e5408eb21cf911141ffd6aad9575df9d598c08238a6a8d690b9f9b002787fc092be44219e16edcc61b8d986f53541ssdeep: 3072:BCAqGQzOJCLU7yxn5mi0Z/PCCFsoU1upEU3YR021iQQxAOrxlf+AVxaO4V:B0ziCw7yx5yZ/P1I1uLsaxAMxp94Vtype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Adware.ConvertAd.134 also known as:

Bkav W32.EmotetNTI.Trojan
Elastic malicious (high confidence)
DrWeb Trojan.Emotet.844
MicroWorld-eScan Gen:Variant.Adware.ConvertAd.134
FireEye Generic.mg.4b3664bb61f9444e
McAfee GenericRXAA-AA!4B3664BB61F9
Malwarebytes Trojan.Downloader
Sangfor Malware
K7AntiVirus Proxy-Program ( 00568b451 )
BitDefender Gen:Variant.Adware.ConvertAd.134
K7GW Proxy-Program ( 00568b451 )
Cybereason malicious.b61f94
BitDefenderTheta AI:Packer.6A4C652D1E
Cyren W32/Emotet.XC.gen!Eldorado
Symantec ML.Attribute.HighConfidence
APEX Malicious
Avast Win32:BankerX-gen [Trj]
ClamAV Win.Trojan.Emotet-6736162-1
Kaspersky not-a-virus:HEUR:AdWare.Win32.Neoreklami.vho
NANO-Antivirus Virus.Win32.Gen.ccmw
Ad-Aware Gen:Variant.Adware.ConvertAd.134
Comodo TrojWare.Win32.Emotet.FSA@8okwk9
Invincea Generic ML PUA (PUA)
McAfee-GW-Edition BehavesLike.Win32.Generic.dh
Emsisoft Gen:Variant.Adware.ConvertAd.134 (B)
Ikarus Trojan-Banker.Emotet
Webroot W32.Trojan.Emotet
Avira TR/Emotet.Gen
MAX malware (ai score=67)
Microsoft Trojan:Win32/Emotet
Arcabit Trojan.Adware.ConvertAd.134
ZoneAlarm not-a-virus:HEUR:AdWare.Win32.Neoreklami.vho
GData Gen:Variant.Adware.ConvertAd.134
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win32.Emotet.C3509390
Acronis suspicious
VBA32 BScope.Trojan.Emotet
ALYac Gen:Variant.Adware.ConvertAd.134
Cylance Unsafe
ESET-NOD32 a variant of Win32/TrojanProxy.Emotet.B
Rising Trojan.Generic@ML.98 (RDML:GwmaYwBn1ygHzia7D7L2zg)
Yandex Trojan.GenAsa!GpdpC4/awIg
eGambit Unsafe.AI_Score_82%
Fortinet W32/Emotet.844!tr
AVG Win32:BankerX-gen [Trj]
CrowdStrike win/malicious_confidence_60% (D)
Qihoo-360 HEUR/QVM20.1.3F29.Malware.Gen

How to remove Adware.ConvertAd.134?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

About “Trojan:Win32/Vidar!MSR” infection

The Trojan:Win32/Vidar!MSR is considered dangerous by lots of security experts. When this infection is active,…

2 mins ago

Generik.BKSFVZU removal tips

The Generik.BKSFVZU is considered dangerous by lots of security experts. When this infection is active,…

9 mins ago

How to remove “Win32/Danmec.C”?

The Win32/Danmec.C is considered dangerous by lots of security experts. When this infection is active,…

14 mins ago

About “Lazy.462416” infection

The Lazy.462416 is considered dangerous by lots of security experts. When this infection is active,…

35 mins ago

Trojan.Generic.35568731 information

The Trojan.Generic.35568731 is considered dangerous by lots of security experts. When this infection is active,…

35 mins ago

What is “Generic.Malware.Ydr.7B09EE28”?

The Generic.Malware.Ydr.7B09EE28 is considered dangerous by lots of security experts. When this infection is active,…

44 mins ago