Malware

Should I remove “AdWare.Win32.Agent.xxypcm”?

Malware Removal

The AdWare.Win32.Agent.xxypcm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.Agent.xxypcm virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine AdWare.Win32.Agent.xxypcm?


File Info:

name: 570D853FC55DF4ACDF69.mlw
path: /opt/CAPEv2/storage/binaries/60d00a6aa0d2c0fce7b59536e7b5fe6aeaa31f86e7f01e7af0292452f217d9fc
crc32: A5D1654D
md5: 570d853fc55df4acdf697b391100a17e
sha1: 841df3b0d9aceade68d0e8e9ee19dc028fdf9b70
sha256: 60d00a6aa0d2c0fce7b59536e7b5fe6aeaa31f86e7f01e7af0292452f217d9fc
sha512: ce6d00be9ae6acab8d4a0cce20facb6f2da95dfa222a139be7597dcdfba94c92d18a800aae4551dacc06b867c66e1be734dd2de124209fba2f1e794b29a3f0de
ssdeep: 12288:ahxp3lZnT9bD8R3HSDllbHP9Ke4ZttFvLM5/KBciznGrKF:aJlh9bD8RXOllbl2tFvLMYBP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F1C40112B6D2C8B3D52258315929EB25E57CB4200F64996FE7D40DBDAE301D0B72AFB3
sha3_384: 3fdb342629fc36bb28e0bdfe93f5e880072a36681ce4a4b968968add273c7accd7f896f1550e4bfc219df81e87b26c0a
ep_bytes: e899040000e980feffff3b0db8914300
timestamp: 2016-08-14 19:15:49

Version Info:

0: [No Data]

AdWare.Win32.Agent.xxypcm also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanTrojan.GenericKD.31550504
FireEyeGeneric.mg.570d853fc55df4ac
ALYacTrojan.GenericKD.31550504
CylanceUnsafe
ZillyaAdware.Agent.Win32.147550
SangforAdware.Win32.Agent.xxypcm
AlibabaAdWare:Win32/Generic.57948744
Cybereasonmalicious.fc55df
VirITTrojan.Win32.MulDrop8.BZWB
APEXMalicious
Kasperskynot-a-virus:AdWare.Win32.Agent.xxypcm
BitDefenderTrojan.GenericKD.31550504
NANO-AntivirusRiskware.Win32.Drop.fptobg
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.31550504
SophosMal/Generic-S + Troj/Agent-AZOL
ComodoMalware@#1ljl9d5jcgf6s
DrWebTrojan.MulDrop8.35049
McAfee-GW-EditionBehavesLike.Win32.Dropper.hc
EmsisoftTrojan.GenericKD.31550504 (B)
GDataTrojan.GenericKD.31550504
JiangminAdware.Agent.alps
WebrootW32.Trojan.GenKD
GridinsoftRansom.Win32.Bladabindi.sa
ArcabitTrojan.Generic.D1E16C28
ViRobotTrojan.Win32.Z.Agent.594676
MicrosoftBackdoor:Win32/Bladabindi!ml
CynetMalicious (score: 100)
McAfeeRDN/Generic.dmk
MAXmalware (ai score=55)
VBA32Trojan.MulDrop
MalwarebytesAdware.Agent
RisingPUA.Presenoker!8.F608 (CLOUD)
MaxSecureTrojan.Malware.73650652.susgen
FortinetW32/Agent.AZOL!tr
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove AdWare.Win32.Agent.xxypcm?

AdWare.Win32.Agent.xxypcm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment