Adware

Adware.Gator removal instruction

Malware Removal

The Adware.Gator is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Gator virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Installs a browser addon or extension
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

raven.veloz.com
www.flowgo.com
update.thunderdownloads.com
www.hugedomains.com
ocsp.digicert.com
crl4.digicert.com
crl3.digicert.com

How to determine Adware.Gator?


File Info:

crc32: 668D8C1F
md5: 9c6da4fae2b7d6607c93c928fcb444f2
name: kylesmomisabeeeach.exe
sha1: 81d96e697ad98f41cdd095a1505f03b5ff162434
sha256: 378e28aca645de011fbfa560efe53e28cb531b660d4b0275a29c159c1dc60c13
sha512: 300c4e733273ad306286335dd79af8b6c3c0966135b856ea0f6be5e21d1cb57bca01f820964833819c323a642fefe015465776e41e30782a4416227e7fcd5afe
ssdeep: 49152:xEhLYLHonetkFktgBPvTLi4ksZ6YTxyw6uUHog8u4AQLsVl5:mhMzoybgBPbesoYpzU2uaLsVl5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: WebDevAZ
FileDescription: Kyles Mom is a Beeeach
FileVersion:
CompanyName: WebDevAZ

Adware.Gator also known as:

MicroWorld-eScanGen:Adware.Heur.ns3@RmL@z9gi
FireEyeGen:Adware.Heur.ns3@RmL@z9gi
MalwarebytesAdware.Gator
VIPRETrojan.Win32.Generic!BT
AegisLabAdware.Win32.Sidesearch.2!c
BitDefenderGen:Adware.Heur.ns3@RmL@z9gi
Cybereasonmalicious.ae2b7d
CyrenW32/AdInstall.A.gen!Eldorado
SymantecAdware.Keenval
TrendMicro-HouseCallTROJ_GEN.R002C0RH420
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:AdWare.Win32.Sidesearch.d
AlibabaTrojanDownloader:Win32/Keenval.e9d0039b
NANO-AntivirusRiskware.Win32.Sidesearch.fbakcz
ViRobotSpyware.Keenval.Do.2323800
RisingDownloader.Keenval!8.3161 (CLOUD)
Ad-AwareGen:Adware.Heur.ns3@RmL@z9gi
SophosGeneric PUA MH (PUA)
F-SecureAdware.ADWARE/Adware.Gen
DrWebTrojan.KeenValAd
TrendMicroTROJ_GEN.R002C0RH420
EmsisoftGen:Adware.Heur.ns3@RmL@z9gi (B)
APEXMalicious
F-ProtW32/AdInstall.A.gen!Eldorado
AviraADWARE/Adware.Gen
MAXmalware (ai score=100)
ArcabitAdware.Heur.EAD1131
ZoneAlarmnot-a-virus:AdWare.Win32.Sidesearch.d
MicrosoftTrojan:Win32/Vigorf.A
CynetMalicious (score: 85)
McAfeeArtemis!9C6DA4FAE2B7
CylanceUnsafe
PandaAdware/SideSearch
ESET-NOD32a variant of Win32/Adware.SideSearch.F
FortinetAdware/SideSearch
TencentWin32.Adware.Sidesearch.Hvjh
Ikarusnot-a-virus:AdWare.Win32.NewDotNet
GDataGen:Adware.Heur.ns3@RmL@z9gi
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Dropper.6c8

How to remove Adware.Gator?

Adware.Gator removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment