Adware

Should I remove “Adware.Searcher”?

Malware Removal

The Adware.Searcher is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Searcher virus can do?

  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Adware.Searcher?


File Info:

crc32: 6171524E
md5: a7d020265d2a19bc76ea77c6f00eb2fd
name: tmpvi_k0dmk
sha1: b7c89cb4c9e1f64967db2c01d31e5fa6e613a2ce
sha256: 640b274b1928f1f38124866a1773672ca66db68f1a019085660130dfe1ceeffa
sha512: 018a672a1251c67bf85a723cc0d94c0802ae24d26a046fabec0b1c049327f47b7c80113f30ac7eee7baa04ca10e10ec560be3d85d991c4ce3723543bc95d5c76
ssdeep: 49152:fLjLwruOvwafWUEBQeN+IOs7qSRBZEVuxtRiILYgrU/a:+uOhwBYInR/uuxtRiILrQ/a
type: PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive

Version Info:

LegalCopyright: (C)
ProductName:
FileVersion:
FileDescription: Producer shd
Translation: 0x0804 0x04e4

Adware.Searcher also known as:

MicroWorld-eScanTrojan.GenericKD.31747835
FireEyeGeneric.mg.a7d020265d2a19bc
CAT-QuickHealW32.Ramnit.A
Qihoo-360QVM42.0.Malware.Gen
ALYacTrojan.GenericKD.31747835
CylanceUnsafe
K7AntiVirusTrojan ( 0050b64b1 )
BitDefenderTrojan.GenericKD.31747835
K7GWTrojan ( 0050b64b1 )
Cybereasonmalicious.65d2a1
TrendMicroPE_RAMNIT.H
BitDefenderThetaAI:FileInfector.EAEEA7850C
F-ProtW32/Ramnit.B!Generic
ESET-NOD32a variant of NSIS/TrojanDropper.Agent.BT
BaiduMulti.Threats.InArchive
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Ramnit-1847
GDataTrojan.GenericKD.31747835
KasperskyVirus.Win32.Nimnul.a
NANO-AntivirusVirus.Win32.Ramnit.eslalb
AvastWin32:RmnDrp
TencentMalware.Win32.Gencirc.10b3ee0c
Ad-AwareTrojan.GenericKD.31747835
SophosW32/Patched-I
F-SecureMalware.W32/Ramnit.CD
DrWebAdware.Searcher.1222
ZillyaTrojan.Zbot.Win32.188716
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.BadFile.vc
Trapminemalicious.high.ml.score
EmsisoftAdware.Dropper (A)
SentinelOneDFI – Malicious PE
CyrenW32/Ramnit.B!Generic
WebrootW32.Malware.Heur
AviraW32/Ramnit.CD
Antiy-AVLGrayWare/Win32.StartPage.gen
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1E46EFB
ZoneAlarmVirus.Win32.Nimnul.a
MicrosoftVirus:Win32/Ramnit.A
Acronissuspicious
McAfeeArtemis!A7D020265D2A
MAXmalware (ai score=81)
VBA32Adware.Searcher
MalwarebytesTrojan.ChinAd
ZonerTrojan.Win32.Ramnit.23698
TrendMicro-HouseCallPE_RAMNIT.H
RisingVirus.Ramnit!1.9AA5 (CLOUD)
IkarusVirus.Ramnit
AVGWin32:RmnDrp
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureVirus.Nimnul.A

How to remove Adware.Searcher?

Adware.Searcher removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment