Adware

Adware.SystemSecurity information

Malware Removal

The Adware.SystemSecurity is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.SystemSecurity virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Queries information on disks, possibly for anti-virtualization
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Adware.SystemSecurity?


File Info:

crc32: 506E29C3
md5: ef3913b42fab6dc2091e888cd9798ead
name: EF3913B42FAB6DC2091E888CD9798EAD.mlw
sha1: 583ecfd8f07bb27908405b0d0bb207241db41c55
sha256: 1a36a29247103284ca95f00949846a75c702fc5347dd7d8e815e6a8c9802e299
sha512: 90fbac1aa7d1986302d5f04c52c61815f03e04ef51457f1a0652f2c94feafcd3553aa0e400cf28280f7888e9b0154144becf0b796375861e1422573b14f25083
ssdeep: 12288:nIonZe/AGFj4kJO1hVHx5otYx1nNewvSAtc8nOMS04X:nIoZeB54kk1TR5Q0QYVycORr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2008 g10 Code GmbH
FileVersion: 2.1.0.1608
CompanyName: g10 Code GmbH
LegalTrademarks:
Comments: GPG4Win is Free Software; you can redistribute it and/or modify it under the terms of the GNU General Public License. You should have received a copy of the GNU General Public License along with this software; if not, write to the Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA
ProductName: GPG4Win (2.1.0-rc1)
FileDescription: Gpg4win: The GNU Privacy Guard and Tools for Windows
Translation: 0x0000 0x04e4

Adware.SystemSecurity also known as:

K7AntiVirusAdware ( 004ba19b1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Fakealert.20418
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.283542
CylanceUnsafe
ZillyaDownloader.FraudLoad.Win32.20641
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWAdware ( 004ba19b1 )
Cybereasonmalicious.42fab6
CyrenW32/FakeAlert.MA.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Adware.SystemSecurity.AG
APEXMalicious
AvastWin32:Tedroo-F [Trj]
ClamAVWin.Dropper.Zeus-9828870-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.283542
NANO-AntivirusRiskware.Win32.SMWnd.bnjrso
ViRobotTrojan.Win32.A.Downloader.659968.E
MicroWorld-eScanGen:Variant.Zusy.283542
TencentMalware.Win32.Gencirc.10b58573
Ad-AwareGen:Variant.Zusy.283542
SophosMal/Generic-R + Mal/FakeAV-GQ
ComodoTrojWare.Win32.Downloader.Fraudload.gh@4lnkey
BitDefenderThetaGen:NN.ZexaF.34236.Oq0@ayPCPIeI
VIPRETrojan.Win32.FakeAV.gq (v)
TrendMicroTROJ_FRAUD.SMWZ
McAfee-GW-EditionPWS-Zbot.gen.ia
FireEyeGeneric.mg.ef3913b42fab6dc2
EmsisoftGen:Variant.Zusy.283542 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.FraudLoad.zhh
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_80%
Antiy-AVLTrojan/Generic.ASMalwS.171E45
MicrosoftTrojan:Win32/Bulta!rfn
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
GDataGen:Variant.Zusy.283542
TACHYONTrojan/W32.Agent.659968.AP
AhnLab-V3Trojan/Win32.FakeAV.R3480
Acronissuspicious
McAfeePWS-Zbot.gen.ia
MAXmalware (ai score=83)
VBA32Trojan.ExpProc.014
MalwarebytesAdware.SystemSecurity
PandaGeneric Malware
TrendMicro-HouseCallTROJ_FRAUD.SMWZ
RisingTrojan.Generic@ML.100 (RDML:8ptl9tw0sTrgvBC3n3cFXw)
YandexTrojan.DL.FraudLoad!kABwdQoBLeo
IkarusTrojan-Downloader.Win32.FraudLoad
FortinetW32/BrowHost.KP!tr
AVGWin32:Tedroo-F [Trj]
Paloaltogeneric.ml

How to remove Adware.SystemSecurity?

Adware.SystemSecurity removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment