Malware

What is “AdWare.Win32.Agent.xxzama”?

Malware Removal

The AdWare.Win32.Agent.xxzama is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.Agent.xxzama virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine AdWare.Win32.Agent.xxzama?


File Info:

name: 55F070DF3CC6AF035345.mlw
path: /opt/CAPEv2/storage/binaries/78cf82602ad5a31bead7e92599b04746448177da1dff55ab83a55acaea507366
crc32: 0856D000
md5: 55f070df3cc6af035345233981732092
sha1: 18403143380b4d37580765a642c2c0b136650dab
sha256: 78cf82602ad5a31bead7e92599b04746448177da1dff55ab83a55acaea507366
sha512: 994a077b2e2987507913efc17821f0c2327729fcb3b3269a33aa0e0276b755261d0e330d105f1118dc8a14251ec55082a5a18ec3d2cb87d8ea8eb9656bcd1f8f
ssdeep: 49152:7l89CgKEFkatOrKjbscZEfHx2/9sZm0fdj6vXgMNaMPQp2:ICfzbOt4R2/9sbFYXgMLPQY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15E8523BEBF01EF1ECC4261B84406EC39A5C06D7CB020975A2DE5BE5BB5F7466EC60096
sha3_384: 257767a797a59013a8c98032d24a996e95ee267ae149c04b481cda64ecbed2a4bfda4547a0bdb1a999b01ab1e42ca314
ep_bytes: 6801605d00e801000000c3c3ce8caf15
timestamp: 2021-12-06 15:42:13

Version Info:

CompanyName: Huge Co Ltd
FileDescription: Huge BRUSH
FileVersion: 1.0.0.1
InternalName: HugeBRUSH.exe
LegalCopyright: Copyright 2021.
OriginalFilename: HugeBRUSH.exe
ProductName: HugeBRUSH
ProductVersion: 1.0.0.1
Translation: 0x0409 0x04e4

AdWare.Win32.Agent.xxzama also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.Convagent.2!c
DrWebTrojan.Siggen15.65207
MicroWorld-eScanTrojan.GenericKD.47580857
FireEyeTrojan.GenericKD.47580857
McAfeeArtemis!55F070DF3CC6
CylanceUnsafe
ZillyaAdware.Convagent.Win32.1453
AlibabaAdWare:Win32/Generic.ee1d3110
BitDefenderThetaGen:NN.ZexaF.34084.UL1aaas8w4ji
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0WL921
Kasperskynot-a-virus:AdWare.Win32.Agent.xxzama
BitDefenderTrojan.GenericKD.47580857
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.47580857
SophosGeneric PUA BI (PUA)
TrendMicroTROJ_GEN.R002C0WL921
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.47580857 (B)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Generic.D2D606B9
ViRobotTrojan.Win32.Z.Agent.1808256
GDataTrojan.GenericKD.47580857
AhnLab-V3Trojan/Win.Generic.C4848302
ALYacTrojan.GenericKD.47580857
MAXmalware (ai score=86)
VBA32Adware.Convagent
APEXMalicious
FortinetAdware/OpenSUpdater
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove AdWare.Win32.Agent.xxzama?

AdWare.Win32.Agent.xxzama removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment