Adware

Should I remove “Adware.Zugo.4 (B)”?

Malware Removal

The Adware.Zugo.4 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Zugo.4 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Adware.Zugo.4 (B)?


File Info:

name: 44424983B12C0CC8CB35.mlw
path: /opt/CAPEv2/storage/binaries/199acd3c97b5aea656c174cde2bd136136e0f1177d29e43afe94836e7c2e347d
crc32: ED3B644F
md5: 44424983b12c0cc8cb35311fe34fa389
sha1: 1a39105bfedbac5fe6bba98c96c9e654df0fbf46
sha256: 199acd3c97b5aea656c174cde2bd136136e0f1177d29e43afe94836e7c2e347d
sha512: 3a63a3e093729710c2dc0447d5991a711df0b4f832d07a065a72875ae6119651a02b4516a919b5f382bddab56dd593d9fb05bd521d5c09264cb9b8a9949cafcf
ssdeep: 6144:KRvGNtqchxnIIO2PY4XBDQPvC0vTyBROfpFmw5kb:2aEWBCryBRWpAh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13A3423AD396E0D95E825907F35DF5D78949E187F40FF60AABBC58122FC79824B2308B1
sha3_384: e3314882ae0b4998bdd314b4c4513fd3a7ab080206c4399e330cf7d29ee66afa0f64902f48b8ecdb1757aefe807d7ef3
ep_bytes: 60be002045008dbe00f0faff57eb0b90
timestamp: 2021-04-07 02:25:09

Version Info:

0: [No Data]

Adware.Zugo.4 (B) also known as:

LionicRiskware.Win32.Zugo.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.Zugo.4
FireEyeGeneric.mg.44424983b12c0cc8
McAfeeArtemis!44424983B12C
CylanceUnsafe
BitDefenderThetaGen:NN.ZexaF.34084.omGfam3u9Jlj
CyrenW32/Trojan.JIEB-7517
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R011C0PHL21
Paloaltogeneric.ml
BitDefenderGen:Variant.Adware.Zugo.4
AvastWin32:Adware-gen [Adw]
Ad-AwareGen:Variant.Adware.Zugo.4
EmsisoftGen:Variant.Adware.Zugo.4 (B)
TrendMicroTROJ_GEN.R011C0PHL21
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosGeneric PUA BK (PUA)
GDataGen:Variant.Adware.Zugo.4
eGambitUnsafe.AI_Score_99%
MAXmalware (ai score=63)
Antiy-AVLTrojan/Generic.ASMalwS.347E4BB
ViRobotAdware.Zugo.244224
APEXMalicious
MicrosoftPWS:Win32/Zbot!ml
CynetMalicious (score: 100)
AhnLab-V3Adware/Win.Zugo.C4469284
VBA32suspected of Trojan.Downloader.gen
ALYacGen:Variant.Adware.Zugo.4
RisingMalware.Heuristic!ET#89% (RDMK:cmRtazrF5LEpVN5RdWwR9CwHpJUt)
SentinelOneStatic AI – Suspicious PE
FortinetMalicious_Behavior.SB
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.3b12c0

How to remove Adware.Zugo.4 (B)?

Adware.Zugo.4 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment