Adware

How to remove “Adware.RuKometa”?

Malware Removal

The Adware.RuKometa is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.RuKometa virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
fromate.ru

How to determine Adware.RuKometa?


File Info:

crc32: 0B0B0857
md5: b73aa673075833b9c4c7bbe1027defca
name: B73AA673075833B9C4C7BBE1027DEFCA.mlw
sha1: 03990337019773a4c618377220ea6948c48da4a5
sha256: 5ed9699e482158075cf142fd548204189ff775f2f76c94b5eb670ce59e5350d6
sha512: 444b2805ad4122dd67452e83459585324d2d79752f5f1fbb4964d7bedf66adea9fb6a30cd007fca82f6042c24ed99810eaef6ac0b5d05bd9144c1c32c195673c
ssdeep: 6144:CU8LhWk480Naz2vCei44s9eUG4AdCtTf190/+5+ySDowtauInW:C3Vp7zUCe34soUGPi1m/+4LkwUBnW
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

BuildVersion: 7, 16, 13, 1541
Comments: 7, 16, 13, 1541
Translation: 0x0408 0x04b0

Adware.RuKometa also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005249d01 )
LionicTrojan.Win32.Upatre.a!c
Elasticmalicious (high confidence)
DrWebTrojan.LoadMoney.3144
CynetMalicious (score: 100)
ALYacTrojan.BRMon.Gen.4
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 005249d01 )
Cybereasonmalicious.307583
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GBZL
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.BRMon.Gen.4
NANO-AntivirusTrojan.Win32.Upatre.exixot
MicroWorld-eScanTrojan.BRMon.Gen.4
TencentWin32.Trojan.Generic.Pefq
Ad-AwareTrojan.BRMon.Gen.4
SophosMal/Generic-R + Mal/FakeAV-SD
BitDefenderThetaGen:NN.ZexaF.34236.ty0@aWIAR7lc
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXDW-VW!B73AA6730758
FireEyeGeneric.mg.b73aa673075833b9
EmsisoftTrojan.BRMon.Gen.4 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ZPACK.Gen8
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2427492
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.BRMon.Gen.4
Acronissuspicious
McAfeeGenericRXDW-VW!B73AA6730758
MAXmalware (ai score=99)
VBA32BScope.Trojan.LoadMoney
MalwarebytesAdware.RuKometa
PandaTrj/GdSda.A
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GBNL!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Adware.RuKometa?

Adware.RuKometa removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment