Malware

AdWare.Win32.Relevant.scy removal

Malware Removal

The AdWare.Win32.Relevant.scy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.Relevant.scy virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Installs a browser addon or extension
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode patterns malware family
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine AdWare.Win32.Relevant.scy?


File Info:

name: 6AA0CC1CC9374342CAC1.mlw
path: /opt/CAPEv2/storage/binaries/8e92a49fc6ba412ee25d2d06b2b059125d6e6b7310a6ad3f378c6353562af74f
crc32: 3FBA0080
md5: 6aa0cc1cc9374342cac190e6587cfcfa
sha1: b063f4fc6c1ac8af1c2959d85d7ae449592304f2
sha256: 8e92a49fc6ba412ee25d2d06b2b059125d6e6b7310a6ad3f378c6353562af74f
sha512: 7c52e8e89f4950da5d7d95718db9848cc4ed1aac5648c1ac659159828c26b76c3cbd611e304a4dd887b8b121106ec167b3f42eeea4a2acf79125c8ba8bf0f0fc
ssdeep: 196608:feHryJirqLGXWleiY41tv6U6BZIz4rB2Eo9vnGSQvCfqs7:GHrywrqLyziTv6hZIsrB2Eo5nGSwEqs7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14F7633A6469611B1F42C50F13B490F2AF8B36C2B8C5891553B1CB90EDF3FA45836B7E9
sha3_384: f2b1754ccffc6f0f0e525ecab9ab7fa9d77b214ea0f48fd9c59be956b054e75f0077a35a6f39ce64a1b7f5ff3b8bc9f8
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: DVDVideoMedia, Inc.
FileDescription: DVDVideoMedia Free DVD Ripper Setup
FileVersion:
LegalCopyright:
ProductName: DVDVideoMedia Free DVD Ripper
ProductVersion: 2.6
Translation: 0x0000 0x04b0

AdWare.Win32.Relevant.scy also known as:

SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.Win32.Relevant.scy
AvastFileRepMalware [Misc]
TencentWin32.AdWare.Relevant.Xdkl
SophosMal/Generic-S
F-SecureAdware.ADWARE/Relevant.xofdm
DrWebTrojan.PWS.Siggen2.42089
WebrootW32.Trojan.GenKD
AviraADWARE/Relevant.xofdm
ZoneAlarmnot-a-virus:AdWare.Win32.Relevant.scy
VBA32Adware.Relevant
MaxSecureTrojan.Malware.119349994.susgen
FortinetRiskware/NDAoF
AVGFileRepMalware [Misc]
DeepInstinctMALICIOUS

How to remove AdWare.Win32.Relevant.scy?

AdWare.Win32.Relevant.scy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment