Adware

Adware.SuspiciousProcStarter malicious file

Malware Removal

The Adware.SuspiciousProcStarter is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.SuspiciousProcStarter virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Adware.SuspiciousProcStarter?


File Info:

name: 1993EEF133990D38048A.mlw
path: /opt/CAPEv2/storage/binaries/85478e3fa00320cd57b594338576117d2c0a16a32b8f13f577cd4a3382eb0058
crc32: 71F04421
md5: 1993eef133990d38048a5d2ce780a266
sha1: d9f57fd341aa6fe467c76df58071606d0b0af102
sha256: 85478e3fa00320cd57b594338576117d2c0a16a32b8f13f577cd4a3382eb0058
sha512: b9efe110db56b0c9e39060d86df3b4886dbee48e53210eee4d76cef90161e0a351c63ad6269047f9455ab800a98e6ad19cc55fe7715cca08ad983573608b9be1
ssdeep: 24576:ncU1F7exXs9rJCiLO71wqWS/lff1RjIRt9RZ+iNaG3vC:nrv7eYJCiLO71bWS/li/+1aC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18B355A11BDC570B7C6741E3389666337DB378F070E15AA879FD6DF2CB823240A92616A
sha3_384: 4c2b42f997c912d9fd0a9f6151c9f3763200bf373efde02e3db2721d8d7139e93a5b96ea2f6d9b0ddc767b5efd84dd56
ep_bytes: 558bec6aff6888db4c0068643a490064
timestamp: 2022-03-29 02:10:37

Version Info:

FileVersion: 1.0.0.0
FileDescription: MD5 File Integrity Checker
ProductName: MD5 File Integrity Checker
ProductVersion: 1.0.0.0
CompanyName: XDGAME
LegalCopyright: XDGAME版权所有。
Comments: MD5 File Integrity Checker
Translation: 0x0804 0x04b0

Adware.SuspiciousProcStarter also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lwTm
tehtrisGeneric.Malware
FireEyeGeneric.mg.1993eef133990d38
McAfeeGenericRXAA-AA!1993EEF13399
MalwarebytesFlyStudio.Trojan.MalPack.DDS
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_90% (D)
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
AvastWin32:MiscX-gen [PUP]
SophosGeneric Reputation PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.th
Trapminemalicious.high.ml.score
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.15MOKEC
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumWorm.Win32.Dropper.RA@1qraug
ViRobotTrojan.Win.Z.Flystudio.1146880.D
MicrosoftTrojan:Win32/Wacatac.A!ml
GoogleDetected
AhnLab-V3Malware/Win.Malware-gen.R487499
VBA32Adware.SuspiciousProcStarter
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CC823
RisingTrojan.Generic@AI.100 (RDML:QicALvpR/X1aLAK2hrfOVQ)
IkarusPUA.FlyStudio
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat.ZDS
AVGWin32:MiscX-gen [PUP]
Cybereasonmalicious.341aa6
DeepInstinctMALICIOUS

How to remove Adware.SuspiciousProcStarter?

Adware.SuspiciousProcStarter removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment