Malware

AdWare.Win32.Linkury (file analysis)

Malware Removal

The AdWare.Win32.Linkury is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.Linkury virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine AdWare.Win32.Linkury?


File Info:

name: 64AD2AA9CD22CA8192DC.mlw
path: /opt/CAPEv2/storage/binaries/2e0f5410ae8e82db530a28f0b6537f44237b69407e16f9c46238f44ffe969ea1
crc32: 0D4136DA
md5: 64ad2aa9cd22ca8192dcafd8b0de6d2e
sha1: 1d8c5a66bb018fee6ae379f4ea08d5b1b1625167
sha256: 2e0f5410ae8e82db530a28f0b6537f44237b69407e16f9c46238f44ffe969ea1
sha512: f9a3696c2911abeea186a1e8281da68b76acca60269c7ca4a9ff8e46cb4a71598262e7a00bec9c80ac702e0ed4b905d94c9d5ce5f0579fb837d0a357d7fbddaa
ssdeep: 1536:1dvHdjcYMWOrtIX9z/MpC7Ot3jwH91plplplplplplplplplplplplplplplplpq:JtrAtIX9zEOOt3jwdO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DCF4EC0B3F4A2778CB8B1271B8B3658BC71645147B16B9D9CCEE01960B8AD585372BFC
sha3_384: 95221cc80368de93e2864168d5487b2970171db635d34c25dfa5148915729c5a7df3f44b2bd81af97a742c8bd6574ed4
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-05-10 05:38:47

Version Info:

Translation: 0x0000 0x04b0
FileDescription: Network Packet Monitor
FileVersion: 1.0.0.0
InternalName: Nettrans.exe
LegalCopyright: Copyright © 2015
OriginalFilename: Nettrans.exe
ProductName: Network Packet Monitor
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

AdWare.Win32.Linkury also known as:

LionicAdware.Win32.Linkury.2!c
Elasticmalicious (high confidence)
DrWebTrojan.Revizer.1148
MalwarebytesPUP.Optional.Linkury
ZillyaAdware.Linkury.Win32.91016
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
AlibabaAdWare:Win32/Linkury.6ac2d58a
K7GWTrojan ( 700000121 )
SymantecPUA.Smartbar
Kasperskynot-a-virus:HEUR:AdWare.Win32.Linkury.gen
AvastOther:Malware-gen [Trj]
SophosGeneric PUA BN (PUA)
McAfee-GW-EditionBehavesLike.Win32.PUP.bz
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataMSIL.Application.Linkury.O
CynetMalicious (score: 100)
AhnLab-V3Packed/Win.FHH.R420042
McAfeeArtemis!64AD2AA9CD22
VBA32Adware.Linkury
APEXMalicious
YandexPUA.Linkury!Q5QnsRDai3c
IkarusWin32.Patched
FortinetW32/Patched.D92D!tr
AVGOther:Malware-gen [Trj]
PandaTrj/CI.A

How to remove AdWare.Win32.Linkury?

AdWare.Win32.Linkury removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment