Adware

Adware:Win32/AdRotator!pz removal

Malware Removal

The Adware:Win32/AdRotator!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware:Win32/AdRotator!pz virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Adware:Win32/AdRotator!pz?


File Info:

name: 1D5B49C897EA3EC2BDD5.mlw
path: /opt/CAPEv2/storage/binaries/9df9febde056de066a75a3f51c6633ff270a8991caf684065ce10d7053074eb7
crc32: DB9DFE9F
md5: 1d5b49c897ea3ec2bdd572278f540ab3
sha1: 9b543deee1473f641afc4fb63814baa66aa695f5
sha256: 9df9febde056de066a75a3f51c6633ff270a8991caf684065ce10d7053074eb7
sha512: 883c8fc0227b46e434682b54f75727dc0591606c2132dcca6da344fb6137febdb3c7812a2fabb12cc30d93e559a98159d883ccc6008ad824df567dcc61240649
ssdeep: 49152:b7PFnkq9ZaLzUrGvxqUCobkeMpqocx10DGYw7D8KzN/GAWP72TUAAB+c:l/aLzubUmW7D1zodAA
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T14EC58D00FBD9E3BEDA0A397906925F6D586ED628972E3ED3DF140E354025EE1763201E
sha3_384: 93568fa35ac563f2a350c08836ce94dec8cd8350c6c70543ce54fb3e6971aba03329a4c7dd09e785631973331408d9ae
ep_bytes: 8bff558bec837d0c017505e8017d0000
timestamp: 2011-01-24 19:49:40

Version Info:

0: [No Data]

Adware:Win32/AdRotator!pz also known as:

BkavW32.Common.69309456
LionicAdware.Win32.EZula.2!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.1d5b49c897ea3ec2
SkyhighAdware-Loudmo.j
McAfeeAdware-Loudmo.j
MalwarebytesMalware.AI.3790658535
ZillyaAdware.EZula.Win32.1113
SangforTrojan.Win32.Save.a
AlibabaAdWare:Win32/EZula.1a37da84
ArcabitTrojan.Jaik.D18D77
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Primawega.AL
ClamAVWin.Adware.Ezula-973
Kasperskynot-a-virus:AdWare.Win32.EZula.heur
BitDefenderGen:Variant.Jaik.101751
NANO-AntivirusRiskware.Win32.EZula.ispds
MicroWorld-eScanGen:Variant.Jaik.101751
AvastWin32:Ezula-ACP [Adw]
TencentWin32.AdWare.Generic.Snkl
SophosGeneric Reputation PUA (PUA)
F-SecureAdware.ADWARE/Adware.Gen
VIPREGen:Variant.Jaik.101751
EmsisoftGen:Variant.Jaik.101751 (B)
IkarusAdWare.Win32.AdRotator
JiangminAdWare/EZula.dzb
WebrootW32.Adware.Gen
GoogleDetected
AviraADWARE/Adware.Gen
Antiy-AVLGrayWare[AdWare]/Win32.Primawega
KingsoftWin32.Troj.EZula.heur
XcitiumMalware@#1njckwjepsj4i
MicrosoftAdware:Win32/AdRotator!pz
ViRobotAdware.EZula.2687488
ZoneAlarmnot-a-virus:AdWare.Win32.EZula.heur
GDataGen:Variant.Jaik.101751
VaristW32/AdRotator.G.gen!Eldorado
AhnLab-V3Adware/Win32.EZula.R29185
VBA32BScope.Adware.EZula
ALYacGen:Variant.Jaik.101751
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DAM24
RisingAdware.AdRotator!8.101E (TFE:5:rKAJCD6GSER)
YandexTrojan.GenAsa!ssvR0Jc7Vok
MaxSecureTrojan.Malware.1899717.susgen
FortinetAdware/Ezula
AVGWin32:Ezula-ACP [Adw]
DeepInstinctMALICIOUS

How to remove Adware:Win32/AdRotator!pz?

Adware:Win32/AdRotator!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment