Adware

Adware.NaviPromo.7 (B) malicious file

Malware Removal

The Adware.NaviPromo.7 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.NaviPromo.7 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Adware.NaviPromo.7 (B)?


File Info:

crc32: 2A5298D4
md5: dfe36a479f58e4e8989ea3f86612c514
name: dvcfzdxczds.exe
sha1: 4579fc86484e2ed1a80da97cf793263942e60c2a
sha256: 9216a605c27de2c77035e138ecf33eb0b35ae056b816acf13193e0b0fc45fbfb
sha512: c60993c99df3233a7dcbaacfebc2626c9d58a7cc80ee86edab0c45c4f76738fa1c36c638d52e7cf4ca20f1588af19a5844067b9b6a27e5db72fd7906210fec18
ssdeep: 6144:3w2fNdCFOg0B4xrtafU6Fd1mJ0X0ifwS7DaQq:1CIBC4DVmJ0XbfwSs
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) oudenarde 2019
InternalName: McFadden.exe
FileVersion: 7.4.1.2
CompanyName: Cnossus
ProductName: chuddah
ProductVersion: 8.1.6.3
FileDescription: khedivate
OriginalFilename: oudenarde.exe
Translation: 0x0409 0x04b0

Adware.NaviPromo.7 (B) also known as:

MicroWorld-eScanGen:Variant.Adware.NaviPromo.7
FireEyeGeneric.mg.dfe36a479f58e4e8
McAfeeRDN/Generic.hra
ALYacGen:Variant.Adware.NaviPromo.7
SangforMalware
BitDefenderGen:Variant.Adware.NaviPromo.7
K7GWTrojan ( 0055d67c1 )
Cybereasonmalicious.79f58e
BitDefenderThetaGen:NN.ZexaF.33550.tm3@aS9OPpni
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GZLU
TrendMicro-HouseCallTROJ_GEN.R002H0CLE19
AvastWin32:MalwareX-gen [Trj]
GDataGen:Variant.Adware.NaviPromo.7
KasperskyTrojan-Dropper.Win32.Scrop.aago
AlibabaTrojan:Win32/Kryptik.ea710677
NANO-AntivirusTrojan.Win32.Nanocore.gljljl
RisingMalware.Undefined!8.C (TFE:3:HDcOsWFP4t)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Adware.NaviPromo.7 (B)
F-SecureTrojan.TR/Crypt.Agent.knbyo
DrWebTrojan.Nanocore.427
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Jeefo.fc
SentinelOneDFI – Malicious PE
APEXMalicious
AviraTR/Crypt.Agent.knbyo
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Adware.NaviPromo.7
ZoneAlarmTrojan-Dropper.Win32.Scrop.aago
MicrosoftTrojan:Win32/Occamy.C
VBA32BScope.Trojan.Nanocore
MAXmalware (ai score=99)
Ad-AwareGen:Variant.Adware.NaviPromo.7
CylanceUnsafe
PandaAdware/SecurityProtection
IkarusTrojan.Win32.Crypt
FortinetW32/GenKryptik.EADF!tr
AVGWin32:MalwareX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Trojan.Generic

How to remove Adware.NaviPromo.7 (B)?

Adware.NaviPromo.7 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment