Adware

Adware.WindowLivePot (file analysis)

Malware Removal

The Adware.WindowLivePot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.WindowLivePot virus can do?

  • Attempts to connect to a dead IP:Port (9 unique times)
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Korean
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself

Related domains:

p.iekeyword.com
app.iekeyword.com
iekeyword.com
api.quotes.com
fabia-her.com
utarget.ru
track.wg-aff.com

How to determine Adware.WindowLivePot?


File Info:

crc32: 17BAE581
md5: 1790add5a9890f253309ad224ff2b96d
name: 1790ADD5A9890F253309AD224FF2B96D.mlw
sha1: 983fce77ffd73902d3df78aac0e6c984c71fb930
sha256: c6318118c69357825b356e2456c3d3ec9683b937b871bd2c3c51796f19c67ec1
sha512: 024151e19392f9c26af0da8fec9b183f00b3414ff86d21a965ccd6441299c8196651f5dfa082ad6f75e49f9cd0af2f2de83c52079c9ec32de7012e3880158633
ssdeep: 3072:qljWumkxdpGDCC8tERywGMRBkCtVE/Ic8z/hrginiKwCxoutpMJKs90XhR:qljWQxODCCyMnn/kGVEAcC5pyCxoS5
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

LegalCopyright: TODO: (c) . All rights reserved.
InternalName: IEKeyword_EXE.exe
FileVersion: 1.0.0.1
CompanyName: TODO:
ProductName: TODO:
ProductVersion: 1.0.0.1
FileDescription: TODO:
OriginalFilename: IEKeyword_EXE.exe
Translation: 0x0412 0x03b5

Adware.WindowLivePot also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan-Downloader ( 005323b91 )
LionicTrojan.Win32.Scar.luJ3
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader4.49479
CynetMalicious (score: 100)
CAT-QuickHealTrojanDownloader.Fosniw
ALYacGen:Variant.Zusy.316784
CylanceUnsafe
ZillyaTrojan.Fosniw.Win32.1395
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanDownloader:Win32/Fosniw.471c7cf1
K7GWTrojan-Downloader ( 005323b91 )
Cybereasonmalicious.5a9890
BaiduWin32.Trojan-Downloader.Fosniw.a
CyrenW32/Fosniw.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Fosniw.AU
APEXMalicious
AvastWin32:Fosniw-H [Spy]
ClamAVWin.Trojan.Fosniw-2
KasperskyTrojan.Win32.Scar.eakj
BitDefenderGen:Variant.Zusy.316784
NANO-AntivirusTrojan.Win32.Agent.brjyia
ViRobotTrojan.Win32.A.Scar.254464.BD
MicroWorld-eScanGen:Variant.Zusy.316784
TencentWin32.Trojan.Scar.Dzae
Ad-AwareGen:Variant.Zusy.316784
SophosMal/Generic-R + Mal/Fosniw-D
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaGen:NN.ZexaF.34294.pu0@au4SmDgG
VIPRETrojan-Downloader.Win32.Fosniw.c (v)
TrendMicroTROJ_AGENT_008606.TOMB
McAfee-GW-EditionBehavesLike.Win32.Generic.dm
FireEyeGeneric.mg.1790add5a9890f25
EmsisoftGen:Variant.Zusy.316784 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Scar.qfh
AviraTR/Agent.233472.31
eGambitUnsafe.AI_Score_98%
MicrosoftTrojanDownloader:Win32/Fosniw.C
GDataGen:Variant.Zusy.316784
AhnLab-V3Trojan/Win.Adload.R438051
Acronissuspicious
McAfeeGenericRXAA-AA!1790ADD5A989
MAXmalware (ai score=87)
VBA32BScope.Trojan.Occamy
MalwarebytesAdware.WindowLivePot
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_AGENT_008606.TOMB
RisingTrojan.IEKeyword!1.6A27 (CLASSIC)
YandexTrojan.GenAsa!g8Y4rESxEg4
IkarusGen.Variant.Cudos
MaxSecureP2P-Worm.Palevo.bhnc
FortinetW32/Dloader.ANW!tr
AVGWin32:Fosniw-H [Spy]
Paloaltogeneric.ml

How to remove Adware.WindowLivePot?

Adware.WindowLivePot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment