Adware

Adware.PennyBee.18 (file analysis)

Malware Removal

The Adware.PennyBee.18 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.PennyBee.18 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Adware.PennyBee.18?


File Info:

name: BE94B3411DDE7E07D7A4.mlw
path: /opt/CAPEv2/storage/binaries/0d2fc21c7934c1fd23036afcd80736f1d166b60b55708acc6e0628301fec5d79
crc32: C416A67C
md5: be94b3411dde7e07d7a418fbc11ec743
sha1: 13877996de3a08763d6231d14864790d6bd2947d
sha256: 0d2fc21c7934c1fd23036afcd80736f1d166b60b55708acc6e0628301fec5d79
sha512: a63bba92bde14f8ee1b24bc8ed920ee172ed9891a7aa451d3aaa0c350cc1c3063230d34ccb5afe4460680872d3946d204dc5f6e3cb6a53a97134edb8767b8413
ssdeep: 49152:73BVfRHaOIDZH8iO9SU7RsgQAH5YaDUTX77vvDVpnFbXrvNOeMzMbsOqlxVKYQ74:bfRHaOIDZH8iOH9sgQA6aDUn7vvBpnFi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E1D59D313BD08076C2733232860EE7B9A6EDE6715D755247A2A01B7C3F349D2592C6AF
sha3_384: 34d2c1d2faf28bbe3647f8ce71c46436c62311d03347c26d7338b53a56168eee176149f2e434eb649872ba2e418af86b
ep_bytes: e877ec0000e989feffff8bff558bec83
timestamp: 2023-01-14 15:45:21

Version Info:

0: [No Data]

Adware.PennyBee.18 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Lotok.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.PennyBee.18
FireEyeGen:Variant.Adware.PennyBee.18
SkyhighGenericRXUD-LR!BE94B3411DDE
McAfeeGenericRXUD-LR!BE94B3411DDE
Cylanceunsafe
ZillyaTrojan.GenKryptik.Win32.163129
SangforBackdoor.Win32.Kryptik.V916
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Farfli.7544dce3
K7GWTrojan ( 00591aa91 )
K7AntiVirusTrojan ( 00591aa91 )
BitDefenderThetaGen:NN.ZexaF.36802.2wW@aWaIU1di
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FTJS
APEXMalicious
ClamAVWin.Trojan.Mikey-9973650-0
KasperskyHEUR:Backdoor.Win32.Lotok.gen
BitDefenderGen:Variant.Adware.PennyBee.18
NANO-AntivirusTrojan.Win32.Lotok.jumogd
AvastWin32:RATX-gen [Trj]
TencentMalware.Win32.Gencirc.13b480ee
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1366819
DrWebTrojan.MulDrop20.48041
VIPREGen:Variant.Adware.PennyBee.18
EmsisoftGen:Variant.Adware.PennyBee.18 (B)
SentinelOneStatic AI – Suspicious PE
GoogleDetected
AviraHEUR/AGEN.1366819
VaristW32/Trojan.IZD.gen!Eldorado
Antiy-AVLTrojan/Win32.GenKryptik
KingsoftWin32.Hack.Lotok.gen
MicrosoftBackdoor:Win32/Farfli!pz
XcitiumMalware@#2jkir6wz3u9g0
ArcabitTrojan.Adware.PennyBee.18
ViRobotTrojan.Win32.Z.Zusy.2987520.N
ZoneAlarmHEUR:Backdoor.Win32.Lotok.gen
GDataGen:Variant.Adware.PennyBee.18
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R513150
Acronissuspicious
ALYacGen:Variant.Adware.PennyBee.18
MalwarebytesCrypt.Trojan.MSIL.DDS
PandaTrj/Genetic.gen
RisingTrojan.Generic@AI.100 (RDML:2cEDgULCuuufjKSiAsezPA)
YandexTrojan.GenKryptik!1Hyqhsiyz9Q
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.102820574.susgen
FortinetW32/GenKryptik.FTJS!tr
AVGWin32:RATX-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudBackdoor

How to remove Adware.PennyBee.18?

Adware.PennyBee.18 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment