Malware

Should I remove “AdWare.Win32.Ruco.cxd”?

Malware Removal

The AdWare.Win32.Ruco.cxd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.Ruco.cxd virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to modify desktop wallpaper

How to determine AdWare.Win32.Ruco.cxd?


File Info:

name: B2596684ABE381ACADF5.mlw
path: /opt/CAPEv2/storage/binaries/7f0ec6def7ce13f28087607b41a3e7d045cd83c7ab36fc1ec3a628cf313312ce
crc32: DA475F6F
md5: b2596684abe381acadf59a788891de15
sha1: 9ad72e51df9759284c5a7a57eda9951ded6b32a1
sha256: 7f0ec6def7ce13f28087607b41a3e7d045cd83c7ab36fc1ec3a628cf313312ce
sha512: 4cdedcc2b92f72b3ba6624375653a0ea9c809cfefa9881f33bc21d1986e8672a07b03833a64bb1da369fdcc63ab8cfa6f294d281c5c76cfb2c1d1467fc3d1ac8
ssdeep: 98304:xaseMy4Ja6UkTMXAPdDcn2BlJPD8Nzl2UT8mRaw8GFvuztrccw47e0WXLO:beJA1UkTMXgnt8NaLwJ+If4u7O
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16B5633EE133C8A17FBA53C3DB4B72E329F647C476C78559E12D23858287275A2809F25
sha3_384: f7f96a498ea288da58c1243ecbe110cd730f3af66fc884eeaf6e662cd60482be1eced58255bd4d8c2581d39ce886c139
ep_bytes: 60be0090a5008dbe00809aff57eb0b90
timestamp: 2020-02-19 08:30:28

Version Info:

FileVersion: 6.1.20.220
LegalCopyright: Copyright © 2013-2015
ProductVersion: 6.1.20.220
授权方式: arFi
Translation: 0x0804 0x04b0

AdWare.Win32.Ruco.cxd also known as:

LionicAdware.Win32.Ruco.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.32870993
FireEyeGeneric.mg.b2596684abe381ac
ALYacTrojan.GenericKD.32870993
CylanceUnsafe
ZillyaAdware.Ruco.Win32.496
SangforSuspicious.Win32.HSTR.AutoitItV3ModGUIDMark
K7AntiVirusTrojan ( 700000111 )
AlibabaTrojan:Win32/Generic.53e64bb5
K7GWTrojan ( 700000111 )
Cybereasonmalicious.4abe38
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Autoit.Y suspicious
APEXMalicious
AvastWin32:Trojan-gen
Kasperskynot-a-virus:AdWare.Win32.Ruco.cxd
BitDefenderTrojan.GenericKD.32870993
Ad-AwareTrojan.GenericKD.32870993
EmsisoftTrojan.GenericKD.32870993 (B)
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DKJ21
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.vc
SophosMal/Generic-S
Paloaltogeneric.ml
GDataTrojan.GenericKD.32870993 (2x)
AviraHEUR/AGEN.1200427
Antiy-AVLTrojan/Generic.ASCommon.1B8
MicrosoftTrojan:Win32/Skeeyah.A!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Skeeyah.C4686996
McAfeeArtemis!B2596684ABE3
MAXmalware (ai score=89)
VBA32Adware.Ruco
MalwarebytesMalware.AI.1184163276
TrendMicro-HouseCallTROJ_GEN.R002C0DKJ21
RisingTrojan.Obfus/Autoit!1.C72A (CLASSIC)
FortinetRiskware/Application
AVGWin32:Trojan-gen
PandaTrj/CI.A
MaxSecureTrojan.Malware.121699436.susgen

How to remove AdWare.Win32.Ruco.cxd?

AdWare.Win32.Ruco.cxd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment