Adware

What is “Adware:Win32/Blackmoon!mclg”?

Malware Removal

The Adware:Win32/Blackmoon!mclg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware:Win32/Blackmoon!mclg virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Adware:Win32/Blackmoon!mclg?


File Info:

name: 9AD30F807964DA1A02A3.mlw
path: /opt/CAPEv2/storage/binaries/2d3d5c1a510272b4d33e2bdd35f163d0db1eb35f332ea064feacd5bff65d5c82
crc32: 5CD1A288
md5: 9ad30f807964da1a02a3e7821eb42730
sha1: f2aecd127b442598d77672069c29d7714de1a67c
sha256: 2d3d5c1a510272b4d33e2bdd35f163d0db1eb35f332ea064feacd5bff65d5c82
sha512: 28205fb221013ebd6f58f12d9f9c43333e821edd842fa4b349b31d4a29170cf76c5014ade769899280691a4b11beeec0f5fc6ea25670a4bf9d5dd5efecfe31fc
ssdeep: 384:yl7zIsnxLLE4b6AXKYvHYG5umTovlE5K8OHulOOY6zpzyTXyHMQik57h6kk:ylvI8LECrKDG5uYmp89lOOY6z0TXyMMe
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T159A2C02ABFBA2076C4411BB831FD20A515FAA999CFC1874F2540B1AFA91DA14D338673
sha3_384: ea420712399b0bfd547b9d3f5042b29c1444f4c2e25b14371073eb388998a51434529d6f9f4d8aea54b9452b006afb42
ep_bytes: 807c2408010f85b901000060be006002
timestamp: 2015-01-25 09:58:37

Version Info:

CompanyName: LookIns
FileDescription: LookIns
FileVersion: 1.0.9.7
InternalName: LookIns.exe
LegalCopyright: 客服邮箱 support@lookins.net 永久官网 www.lookins.net (翻墙访问)
OriginalFilename: LookIns.exe
ProductName: LookIns
ProductVersion: 1.0.9.7
Translation: 0x0409 0x04b0

Adware:Win32/Blackmoon!mclg also known as:

LionicTrojan.Win32.Generic.lrlv
Elasticmalicious (moderate confidence)
SkyhighBehavesLike.Win32.Dropper.mc
Cylanceunsafe
ZillyaTrojan.Convagent.Win32.8092
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/VMProtect.f5a2183b
K7GWTrojan ( 005930da1 )
K7AntiVirusTrojan ( 005930da1 )
BitDefenderThetaGen:NN.ZedlaF.36744.bmSfa0TKfFnb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.BlackMoon.A suspicious
APEXMalicious
ClamAVWin.Dropper.Tiggre-9845940-0
KasperskyVHO:Trojan.Win32.Convagent.gen
NANO-AntivirusTrojan.Win32.Dwn.fijujb
AvastWin32:Malware-gen
DrWebTrojan.DownLoader23.48236
SophosGeneric Reputation PUA (PUA)
IkarusTrojan.Win32.VMProtect
JiangminAdWare.Generic.wicc
GoogleDetected
Antiy-AVLTrojan/Win32.Blamon.a
MicrosoftAdware:Win32/Blackmoon!mclg
ZoneAlarmVHO:Trojan.Win32.Convagent.gen
GDataWin32.Trojan-Stealer.BlackMoon.D
CynetMalicious (score: 100)
McAfeeArtemis!9AD30F807964
VBA32BScope.Trojan.Inject
PandaTrj/GdSda.A
RisingTrojan.Convagent!8.12323 (CLOUD)
YandexTrojan.GenAsa!SNEtAMASQH0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.109653022.susgen
FortinetRiskware/Blackmoon
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Adware:Win32/Blackmoon!mclg?

Adware:Win32/Blackmoon!mclg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment