Malware

What is “AdWare.Win32.Burden”?

Malware Removal

The AdWare.Win32.Burden is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.Burden virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
tjv1.znyshurufa.com
a.tomx.xyz

How to determine AdWare.Win32.Burden?


File Info:

crc32: 0B2F362F
md5: 458a98132dec98cd5503aded88db3026
name: setup_1.4.1.19813.exe
sha1: 07db8436c68c456bf8f0de69f108ef852894fc3e
sha256: 42643b6abc2cca849c96a28c19fdb69ebe9ccf9bb16f61febdd6cc585c746f71
sha512: 24361cd26fb4b86c3da5c5dbb63a97372488b2b7fccf9dba5d4c907afcb79e5dff7d8fa67412842f53d9c2c222f1d1ef4ec8fbe2632cc6c55f690b8074b1b206
ssdeep: 196608:tn8DLiMVYhtsgGxG4VPPRuAWTGUtYb6E+LpIDQW3bBoPwnpYre0jQasScpVk+s+j:tOnVYhOxFVPJd1UtcQW3mPYYreuQasS4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2019
InternalName: x5e03x4e01x538bx7f29
FileVersion: 1.4.1.19813
CompanyName: x5e03x4e01x538bx7f29
ProductName: x5e03x4e01x538bx7f29
ProductVersion: 1,4,1,19813
FileDescription: x5e03x4e01x538bx7f29
OriginalFilename: Install.exe
Translation: 0x0804 0x04b0

AdWare.Win32.Burden also known as:

DrWebAdware.Softcnapp.110
FireEyeGeneric.mg.458a98132dec98cd
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 00538f8f1 )
K7GWAdware ( 00538f8f1 )
CyrenW32/Trojan.PGKY-3334
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:HEUR:AdWare.Win32.Burden.gen
NANO-AntivirusRiskware.Win32.Softcnapp.fyceui
RisingAdware.Softcnapp!1.B5FE (CLOUD)
SophosGeneric PUA AH (PUA)
ComodoApplicUnwnt@#24di4j6ek1s64
F-SecurePotentialRisk.PUA/Softcnapp.Gen
ZillyaAdware.Burden.Win32.130
Invinceaheuristic
McAfee-GW-EditionArtemis!PUP
IkarusPUA.Softcnapp
JiangminAdWare.Burden.fr
WebrootW32.Adware.Gen
AviraPUA/Softcnapp.Gen
Endgamemalicious (high confidence)
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Burden.gen
MicrosoftPUA:Win32/Softcnapp
AhnLab-V3PUP/Win32.Softcnapp.R275230
McAfeeArtemis!458A98132DEC
MAXmalware (ai score=99)
VBA32BScope.Adware.Softcnapp
MalwarebytesAdware.Softcnapp
ESET-NOD32a variant of Win32/Softcnapp.J potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R067H0CA920
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_65%
FortinetAdware/Burden
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)

How to remove AdWare.Win32.Burden?

AdWare.Win32.Burden removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment