Adware

Adware.Ruco removal guide

Malware Removal

The Adware.Ruco is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Ruco virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk

How to determine Adware.Ruco?


File Info:

name: D226AE5B4B12BC7B3B40.mlw
path: /opt/CAPEv2/storage/binaries/abc253f96c340803e06e34f27e10efdb337a15df85dada10229c7b2361db2699
crc32: 2FA2D587
md5: d226ae5b4b12bc7b3b40926155a4cff8
sha1: afb50db09f2cb54dfe3fddd068fb27deb22fe385
sha256: abc253f96c340803e06e34f27e10efdb337a15df85dada10229c7b2361db2699
sha512: 2d89097534531be2f87e2e297cb2e90b785ac29df0a6652230ab0aa10270acecd7864a4ddc0e65f6cd666b288c17db7af9835784564d9c5c6b3915bd57b7ef04
ssdeep: 98304:jaB+uYf7FrpxEAPDUkTxe0WlxUDcn2BlJPD8Nzl2UT8mRaw8GFvuztrccwa7:Aq7xISUkTADGnt8NaLwJ+Ifa7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A65633EE27688A27E7E63C39B5B32EA29FB07C57583C41DD16D1381C287166E6814F34
sha3_384: 6211ee0658f99e4ca0c8f412aeb7a8621351d6c3f61189f9d32f52533f15ffeef8525560f763c823de85be5dfaf25ebe
ep_bytes: 60be0040a5008dbe00d09aff57eb0b90
timestamp: 2019-12-09 00:54:06

Version Info:

FileVersion: 16.1.19.1209
LegalCopyright: Copyright © 2013-2015
ProductVersion: 16.1.19.1209
授权方式: arFi
Translation: 0x0804 0x04b0

Adware.Ruco also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop11.34321
MicroWorld-eScanTrojan.GenericKD.42103101
FireEyeGeneric.mg.d226ae5b4b12bc7b
McAfeeArtemis!D226AE5B4B12
CylanceUnsafe
ZillyaAdware.Ruco.Win32.306
SangforTrojan.Win32.Autoit.Y
K7AntiVirusTrojan ( 700000111 )
AlibabaAdWare:Win32/Generic.6e0d6c50
K7GWTrojan ( 700000111 )
Cybereasonmalicious.b4b12b
CyrenW32/Trojan.SXXY-4551
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Autoit.Y suspicious
TrendMicro-HouseCallTROJ_GEN.R002H0CL221
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.Win32.Ruco.vho
BitDefenderTrojan.GenericKD.42103101
NANO-AntivirusTrojan.Win32.Drop.gvczfe
AvastWin32:Trojan-gen
RisingTrojan.Obfus/Autoit!1.C72A (CLASSIC)
Ad-AwareTrojan.GenericKD.42103101
EmsisoftTrojan.GenericKD.42103101 (B)
ComodoMalware@#3q8b1cduqw6vj
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.vc
SophosGeneric PUA KP (PUA)
GDataTrojan.GenericKD.42103101
AviraHEUR/AGEN.1200122
Antiy-AVLTrojan/Generic.ASCommon.1B8
GridinsoftRansom.Win32.Occamy.oa!s2
MicrosoftTrojan:Win32/Occamy.CAB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C3639128
ALYacTrojan.GenericKD.42103101
MAXmalware (ai score=89)
VBA32Adware.Ruco
MalwarebytesMalware.AI.1242857336
APEXMalicious
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Adware.Ruco?

Adware.Ruco removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment