Adware

What is “Adware.ZooZoo.3”?

Malware Removal

The Adware.ZooZoo.3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.ZooZoo.3 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Adware.ZooZoo.3?


File Info:

name: FC6689D5659450B45A17.mlw
path: /opt/CAPEv2/storage/binaries/b755b93d7218e955e2a97f6135e6d5d6988ba053f2c61fbeaf13bd43d3789f11
crc32: 314C86E9
md5: fc6689d5659450b45a17b6a119f824a4
sha1: e827c5c8dafc09d68b777a220bff9752b0a4dc1a
sha256: b755b93d7218e955e2a97f6135e6d5d6988ba053f2c61fbeaf13bd43d3789f11
sha512: b91763fb6c711714bf3d67d760b3599b9d8676fe8212d28ee49ea090f326b031560d7d64be8a42926ccf7f761eed62314aefbe2bf7759fd43f58d7b07be7223c
ssdeep: 24576:yTHTpskspM2/3nOCrpdol4ABCgTvBnEqV:y/2WCrHw4aTKqV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T170258E33F691C0F3C125247119B7573AAEB46E061B25CAD7A3D8DE6A7C32251AB3720D
sha3_384: e1401edf4bf8ee1e99950be5317fa6d1ee225d13821757e18514880df115ab18dec1650715c950c819e8cf23eccd383e
ep_bytes: 558bec6aff68e0384c006834b4480064
timestamp: 2023-06-09 11:36:55

Version Info:

FileVersion: 1.0.0.0
FileDescription: 控制台窗口主机
ProductName: 控制台窗口主机
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 控制台窗口主机
Translation: 0x0804 0x04b0

Adware.ZooZoo.3 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Adware.ZooZoo.3
ClamAVWin.Malware.Trojanx-9884910-0
McAfeeArtemis!FC6689D56594
MalwarebytesTrojan.MalPack.FlyStudio
VIPREGen:Variant.Adware.ZooZoo.3
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.565945
CyrenW32/Trojan.ISO.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Flyagent.NGJ
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:RiskTool.Win32.FlyStudio.cvas
BitDefenderGen:Variant.Adware.ZooZoo.3
AvastWin32:TrojanX-gen [Trj]
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.fc6689d5659450b4
EmsisoftGen:Variant.Adware.ZooZoo.3 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Flyagent.A
JiangminTrojan.Generic.odvl
MAXmalware (ai score=61)
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
ArcabitTrojan.Adware.ZooZoo.3
ZoneAlarmnot-a-virus:RiskTool.Win32.FlyStudio.cvas
MicrosoftProgram:Win32/Wacapew.C!ml
GoogleDetected
BitDefenderThetaGen:NN.ZexaF.36250.7q0@aSj3@Ejb
ALYacGen:Variant.Adware.ZooZoo.3
VBA32BScope.Trojan.Dynamer
Cylanceunsafe
RisingBackdoor.Agent!1.C4E0 (CLASSIC)
IkarusPUA.FlyStudio
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.PHP!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Adware.ZooZoo.3?

Adware.ZooZoo.3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment