Adware

Adware.Generic.1963841 (file analysis)

Malware Removal

The Adware.Generic.1963841 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Generic.1963841 virus can do?

  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Adware.Generic.1963841?


File Info:

crc32: D8687DB7
md5: b27c5be767291963f0457c8983c25b54
name: B27C5BE767291963F0457C8983C25B54.mlw
sha1: a1c9d0de19d7e7b1a798b0ba9f59aef86d86d77d
sha256: d9eb45207e72fa21a506f8f3f34002c4f0f4db305504bbcccc03cec953ab2f25
sha512: 5fb3777f4fa0a8438a507d7ef59bcfed9dc3b296c71403a9e2a607a093e28153f3834203a8beba75b04855bfc0d3c92470b9381ae44845074a9c35526eb91f59
ssdeep: 1536:qpgpHzb9dZVX9fHMvG0D3XJo2X28DdXCyXFuaqsKBMK:ogXdZt9P6D3XJo2X2WC9awBMK
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright:
FileVersion: 8.4.5.114
ProductName:
ProductVersion:
FileDescription:
OriginalFilename: petry.exe
Translation: 0x0000 0x04e4

Adware.Generic.1963841 also known as:

LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
ALYacAdware.Generic.1963841
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/Runner.7f3fd66b
Cybereasonmalicious.767291
CyrenW32/Dotdo.D.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of NSIS/Adware.Runner.B
APEXMalicious
AvastNSIS:AdwareX-gen [Adw]
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderAdware.Generic.1963841
NANO-AntivirusTrojan.Nsis.Dotdo.eyvfyx
ViRobotAdware.Dotdo.66840.W
MicroWorld-eScanAdware.Generic.1963841
TencentWin32.Trojan.Agent.Pdvw
Ad-AwareAdware.Generic.1963841
SophosGeneric PUA KB (PUA)
ComodoApplicUnwnt@#tqsh43lo59c8
F-SecureHeuristic.HEUR/AGEN.1127437
McAfee-GW-EditionBehavesLike.Win32.AdwareDotDo.kh
FireEyeAdware.Generic.1963841
EmsisoftAdware.Generic.1963841 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1127437
MicrosoftTrojan:Win32/Wacatac.A!ml
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
GDataAdware.Generic.1963841
McAfeeArtemis!B27C5BE76729
MAXmalware (ai score=67)
MalwarebytesAdware.DotDo.Generic
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0PIP21
RisingAdware.Dotdo/NSIS!1.B0DB (CLASSIC)
FortinetNSIS/Agent.GU!tr
AVGNSIS:AdwareX-gen [Adw]

How to remove Adware.Generic.1963841?

Adware.Generic.1963841 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment