Adware

Adware.GorillaPrice malicious file

Malware Removal

The Adware.GorillaPrice is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.GorillaPrice virus can do?

  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Adware.GorillaPrice?


File Info:

name: CCB3F0E2735F6F0472B8.mlw
path: /opt/CAPEv2/storage/binaries/31bf65e095ed37293d8fa0818ff7d9c55e53c5de0241d087b5579e915c5369f0
crc32: 3DF0AE69
md5: ccb3f0e2735f6f0472b85d65956d6a51
sha1: 704e79fb5a769403a9fb4167b550499e3f9440de
sha256: 31bf65e095ed37293d8fa0818ff7d9c55e53c5de0241d087b5579e915c5369f0
sha512: eac1787f4a2df0aeef0896318b0bdfd2df8b581c9e2c1c2574e788335cfd8bb285b3526b220b1e4d102b0d18015ed9faffd3de2782e19a22f3ff3c2ccf4bb864
ssdeep: 12288:boqCKVPiwpgbmxZE9VCGFX+IlkloZUtYOTvwbCT:bMagiceGFX+YtZUtYaT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A00549097ECDD0B2D042AFF19C06B5BCA1757B914B4526C3E6943AA74D301D1AA2FEE3
sha3_384: 475372f28f443d770f3047620fd24852da0bcf7404f5bbc699438dfd15a350f74cba30f94bbc8d71ef3f39080bde7c33
ep_bytes: e859c60000e9a4feffff8bff558bec6a
timestamp: 2017-11-24 00:54:21

Version Info:

FileDescription: NetworkCache
FileVersion: 1, 0, 0, 0
InternalName: NetworkCache
LegalCopyright: Copyright (C) 2017
OriginalFilename: ntcache.exe
ProductName: NetworkCache
ProductVersion: 1, 0, 0, 0
Translation: 0x0409 0x04b0

Adware.GorillaPrice also known as:

Elasticmalicious (high confidence)
DrWebTrojan.BrowseBan.1227
MicroWorld-eScanTrojan.Generic.32944695
FireEyeTrojan.Generic.32944695
McAfeeDownloader
ZillyaAdware.GorillaPrice.Win32.2055
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/GorillaPrice.d688d391
CyrenW32/Trojan.GDY.gen!Eldorado
SymantecSMG.Heur!gen
APEXMalicious
CynetMalicious (score: 100)
BitDefenderTrojan.Generic.32944695
SUPERAntiSpywareAdware.Downloader/Variant
AvastOther:Malware-gen [Trj]
TencentMalware.Win32.Gencirc.10b13c58
SophosGeneric Reputation PUA (PUA)
VIPRETrojan.Generic.32944695
McAfee-GW-EditionBehavesLike.Win32.IBryte.cm
EmsisoftTrojan.Generic.32944695 (B)
IkarusPUA.GorillaPrice
GDataTrojan.Generic.32944695
Antiy-AVLTrojan/Win32.TSGeneric
XcitiumApplication.Win32.AdWare.GorillaPrice.A@7feu33
ArcabitTrojan.Generic.D1F6B237
ViRobotAdware.Gorillaprice.865280.FT
MicrosoftBrowserModifier:Win32/Linkhortry
GoogleDetected
AhnLab-V3PUP/Win32.Helper.R225570
Acronissuspicious
ALYacTrojan.Generic.32944695
MAXmalware (ai score=84)
MalwarebytesAdware.GorillaPrice
PandaTrj/CI.A
RisingTrojan.Linkhortry!8.13340 (CLOUD)
SentinelOneStatic AI – Suspicious PE
FortinetRiskware/Dloader
AVGOther:Malware-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (W)

How to remove Adware.GorillaPrice?

Adware.GorillaPrice removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment