Malware

AdWare.Win32.MiniPages.bc malicious file

Malware Removal

The AdWare.Win32.MiniPages.bc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.MiniPages.bc virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid

How to determine AdWare.Win32.MiniPages.bc?


File Info:

name: 9FF3A526CB07EB063934.mlw
path: /opt/CAPEv2/storage/binaries/ad79b669c6a77204e4ee112543e1fb42df53b35c90734c977f4a79ab17d4f58d
crc32: 98037FC6
md5: 9ff3a526cb07eb06393469afc6095ea8
sha1: c6128a6b72351cf87fa4b073c976b1b2f69cfcdb
sha256: ad79b669c6a77204e4ee112543e1fb42df53b35c90734c977f4a79ab17d4f58d
sha512: 1c3e9dea297c092004525ae4631334ae3de1f75d1be65de73ed071a0e2919d35468f88244f5607e622c804715826ee96e7aca8984e3293d96c48faa07dd69a53
ssdeep: 98304:EYQ+JvSaHFgWvvgTMRKMezbiS75yvvod2VHju+5MOzWxpcr8xTqmGd:K+5S0r3gTweJw3osQez0pcraum
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E036237357610005E2D6CC399A27BEF031F22B2A5B81B87455E6BCCE29365ACF217B53
sha3_384: 7045b808deca4b18bd5dc4224f7ea8e4f779ccddbbecf5f809a522ca2445c8e10aafb4194a62ac2b13cf947af5916ec3
ep_bytes: 6879fce0bfe8911a06000fb617c0c45e
timestamp: 2022-01-13 11:00:19

Version Info:

FileDescription: __
FileVersion: 3.2.2.12
InternalName: dt
LegalCopyright: Copyright(@)2022
OriginalFilename: appsetupdt.exe
ProductName: __
ProductVersion: 3.2.2
Translation: 0x0409 0x04e4

AdWare.Win32.MiniPages.bc also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.MiniPages.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.83387
ALYacTrojan.GenericKDZ.83387
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058dcbe1 )
AlibabaAdWare:Win32/MiniPages.08c4a962
K7GWTrojan ( 0058dcbe1 )
Cybereasonmalicious.b72351
CyrenW32/ABRisk.PIYM-9212
ESET-NOD32a variant of Win32/Packed.VMProtect.ACR
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Generic-9936429-0
Kasperskynot-a-virus:AdWare.Win32.MiniPages.bc
BitDefenderTrojan.GenericKDZ.83387
AvastWin32:AdwareX-gen [Adw]
RisingTrojan.Generic@AI.92 (RDML:FZSwrt0F449Tq9m4h+nwqA)
Ad-AwareTrojan.GenericKDZ.83387
SophosGeneric ML PUA (PUA)
DrWebAdware.Duote.1
ZillyaTrojan.Kryptik.Win32.3671169
TrendMicroTROJ_GEN.R03BC0PE922
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.9ff3a526cb07eb06
EmsisoftTrojan.GenericKDZ.83387 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.83387
JiangminAdWare.MiniPages.jm
AviraADWARE/Agent.VX
MAXmalware (ai score=82)
ArcabitTrojan.Generic.D145BB
ViRobotTrojan.Win32.Z.Minipages.5132288.B
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.VV.R473887
McAfeeGenericRXRL-VV!9FF3A526CB07
TACHYONTrojan/W32.Agent.5132288.G
VBA32TScope.Malware-Cryptor.SB
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallTROJ_GEN.R03BC0PE922
TencentPua:Adware.Win32.Downloader.16000223
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.138934534.susgen
FortinetAdware/Duote
BitDefenderThetaGen:NN.ZexaF.34712.@Z0@aq0xs9oj
AVGWin32:AdwareX-gen [Adw]
PandaTrj/CI.A
CrowdStrikewin/grayware_confidence_100% (W)

How to remove AdWare.Win32.MiniPages.bc?

AdWare.Win32.MiniPages.bc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment