Adware

How to remove “Adware.ShopperPro.H”?

Malware Removal

The Adware.ShopperPro.H is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.ShopperPro.H virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Loads a driver
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • Steals private information from local Internet browsers
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Attempts to create or modify a Browser Helper Object
  • Attempts to modify proxy settings

How to determine Adware.ShopperPro.H?


File Info:

name: 6EBB6CFDCAA83EEB5EA8.mlw
path: /opt/CAPEv2/storage/binaries/98d36baefda9a8aa8743a4650b9a5b858e104660d59b3055218447ff350e04b8
crc32: F360B903
md5: 6ebb6cfdcaa83eeb5ea8c30ae10c95b1
sha1: a7acd3f2a10bebc23e048e1b46d5f552a2594daf
sha256: 98d36baefda9a8aa8743a4650b9a5b858e104660d59b3055218447ff350e04b8
sha512: aface167fa13a17993557a6c6073a12f8acacce3435adaa1f9ede39167e6be8d4b9e6420529775532a8c210a320b3f6760b989d5974ddd672021ef43c95f0e0d
ssdeep: 98304:AA4BWiakqZDlhs6Kyls1Hzd6BVoOizEAH4zQKsM74aLJbA:ATBBR6KySzqVoXv4zmM74t
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13B26330FAD435852E632A13F0767298CC057A90977E4249FA0EEA709BC4C7B78AD77D4
sha3_384: c12e6871a523e4b2cf79455db9c491b519accc3891c23b48b61268f2b7e8a2a431dda3f5e21834908ffa719ad2181a48
ep_bytes: 81ec8401000053555633db57895c2418
timestamp: 2014-05-11 20:03:36

Version Info:

FileVersion: 2.5.8305.1489
ProductVersion: 2.5.8305.1489
Translation: 0x0409 0x04e4

Adware.ShopperPro.H also known as:

BkavW32.AIDetect.malware2
LionicAdware.NSIS.Agent.maw5
Elasticmalicious (high confidence)
MicroWorld-eScanAdware.ShopperPro.H
FireEyeGeneric.mg.6ebb6cfdcaa83eeb
CAT-QuickHealAdWare.NSIS.Shopro.A
MalwarebytesPUP.Optional.ShopperPro
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Banker.eum
K7AntiVirusTrojan ( 004b4d4a1 )
BitDefenderAdware.ShopperPro.H
K7GWTrojan ( 004b4d4a1 )
Cybereasonmalicious.dcaa83
ArcabitAdware.ShopperPro.H
CyrenW32/ShopperPro.G.gen!Eldorado
SymantecPUA.Goobzo
ESET-NOD32a variant of Win32/SpeedBit.G potentially unwanted
Paloaltogeneric.ml
CynetMalicious (score: 100)
AlibabaAdWare:Win32/SpeedBit.735f739a
NANO-AntivirusTrojan.Nsis.Drop.dfvfjd
SophosGeneric PUA KH (PUA)
DrWebAdware.Plugin.209
ZillyaAdware.Agent.Win32.41364
McAfee-GW-EditionBehavesLike.Win32.AdwareOutBrowse.rc
SentinelOneStatic AI – Suspicious PE
EmsisoftAdware.ShopperPro.H (B)
APEXMalicious
AviraADWARE/Adware.Gen
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataNSIS.Application.Crypted.C
AhnLab-V3PUP/Win32.CrossRider.R133451
McAfeeArtemis!6EBB6CFDCAA8
MAXmalware (ai score=100)
VBA32Adware.Agent
CylanceUnsafe
PandaTrj/CI.A
WebrootPua.Shopperpro
AVGNSIS:Adware-PQ [PUP]
AvastNSIS:Adware-PQ [PUP]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Adware.ShopperPro.H?

Adware.ShopperPro.H removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment