Adware

Adware.Dropper (A) information

Malware Removal

The Adware.Dropper (A) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Dropper (A) virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

fget-career.com
www.qq5.com
css.jipinfeiche.cn

How to determine Adware.Dropper (A)?


File Info:

crc32: 42CD6BBC
md5: b95f7b489e3bd33835c2d65f6dcbad6b
name: dongwuyuanlianliankan.exe
sha1: ede17110467c850d8d433a46242116a054d756ab
sha256: 25de9ca404542b9dcd2934158372de2c1d1ac46ed6051a0a3e9a7e0596eb2beb
sha512: fae1c1ea3981eeede1462b6e8eeaeee0ed5f2fd00f32cb09e945c9c151a1178534276cc21e731a98635559e07875f4c492621eb3fb95294c57c32e4e4d4aa815
ssdeep: 393216:ugK912kjK4VXNI/6HVrqQcPmsmUjY6mLcDvg0Bv:ugKP2p4V968rqr/YpYD40x
type: PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive

Version Info:

LegalCopyright: (C)
ProductName:
FileVersion:
FileDescription: Producer shd
Translation: 0x0804 0x04e4

Adware.Dropper (A) also known as:

DrWebAdware.Searcher.1222
FireEyeGeneric.mg.b95f7b489e3bd338
CAT-QuickHealW32.Ramnit.A
McAfeeArtemis!B95F7B489E3B
CylanceUnsafe
K7AntiVirusTrojan ( 0050b64b1 )
BitDefenderWin32.Ramnit
K7GWTrojan ( 0050b64b1 )
Cybereasonmalicious.89e3bd
TrendMicroPE_RAMNIT.H
BitDefenderThetaAI:FileInfector.EAEEA7850C
CyrenW32/Ramnit.B!Generic
APEXMalicious
AvastWin32:RmnDrp
ClamAVWin.Trojan.Ramnit-1847
GDataTrojan.GenericKD.32774127
KasperskyVirus.Win32.Nimnul.a
AlibabaVirus:Win32/Nimnul.9b998201
NANO-AntivirusVirus.Win32.Ramnit.eslalb
AegisLabVirus.Win32.Nimnul.n!c
RisingVirus.Ramnit!1.9AA5 (CLASSIC:bWQ1On/VOxVBpt0f0udvDQJDAX4)
SophosMal/Agent-AUG
F-SecureMalware.W32/Ramnit.CD
BaiduMulti.Threats.InArchive
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.BadFile.rc
Trapminemalicious.high.ml.score
EmsisoftAdware.Dropper (A)
IkarusVirus.Ramnit
F-ProtW32/Ramnit.B!Generic
JiangminWin32/PatchFile.et
MaxSecureVirus.Nimnul.A
AviraW32/Ramnit.CD
Endgamemalicious (high confidence)
ArcabitWin32.Ramnit
ZoneAlarmVirus.Win32.Nimnul.a
MicrosoftVirus:Win32/Ramnit.A
Acronissuspicious
VBA32Virus.Win32.Nimnul.a
MAXmalware (ai score=100)
MalwarebytesTrojan.ChinAd
ZonerTrojan.Win32.Ramnit.23698
ESET-NOD32a variant of NSIS/TrojanDropper.Agent.BT
TrendMicro-HouseCallPE_RAMNIT.H
TencentWin32.Virus.Nimnul.Pftf
SentinelOneDFI – Suspicious PE
FortinetW32/Agent.BT!tr
WebrootW32.Malware.Heur
AVGWin32:RmnDrp
CrowdStrikewin/malicious_confidence_70% (W)
Qihoo-360Win32/Virus.IM.0e1

How to remove Adware.Dropper (A)?

Adware.Dropper (A) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment