Adware

Adware:Win32/Clariagain information

Malware Removal

The Adware:Win32/Clariagain is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware:Win32/Clariagain virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • A named pipe was used for inter-process communication
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • Installs a browser addon or extension
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • A possible heap spray exploit has been detected
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Adware:Win32/Clariagain?


File Info:

name: 05E929CC351B539C1BE3.mlw
path: /opt/CAPEv2/storage/binaries/dafe84e6176050260d3b46b6654109e6e1ece0ab2503e064f73c41fe7ba3a9a8
crc32: 115A6F71
md5: 05e929cc351b539c1be30edd6385c598
sha1: 11019089c71c455a8d8ebd29e6ef32f53fd08758
sha256: dafe84e6176050260d3b46b6654109e6e1ece0ab2503e064f73c41fe7ba3a9a8
sha512: 2807039513c5f75e9dd4dd03d8ae5740b96ccdfa516b9f764512a38f68d6797c489baa88ff55ac89efeed1c40fea4cf61110b887eed9c5d58e478192c09adf8e
ssdeep: 24576:xPak5fsjNdOYZ6bCd0xAgVWlpw+du2Ax132/O2t2OCCQ:xj52EYl0CSWlpw+gx9hOCX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T122253379DBB4EFEDEEACE23834207ED5C7185D709A24846F13604FDBA819C588F96090
sha3_384: e5ccf9805b6834ec580310959cfb86d5eda20ad5ef826205681f660fc3d99a9a821385374b3c15cbbcd3dcaaec16a2c7
ep_bytes: 558bec81ec2c0500005356576a015e6a
timestamp: 2000-04-25 14:37:12

Version Info:

CompanyName:
FileDescription: Jack-o-lantern
FileVersion:
LegalCopyright:

Adware:Win32/Clariagain also known as:

LionicAdware.Win32.Gator.2!c
MicroWorld-eScanGen:Adware.Heur.mq1@RSwJxami
McAfeeArtemis!05E929CC351B
K7AntiVirusAdware ( 004ba57c1 )
AlibabaAdWare:Win32/Gator.f11a2590
Cybereasonmalicious.c351b5
CyrenW32/Adware.KPLS-5698
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Adware.Gator
BaiduWin32.Adware.Gator.a
TrendMicro-HouseCallTROJ_GEN.R002H01KP21
Kasperskynot-a-virus:AdWare.Win32.Gator.3013
BitDefenderGen:Adware.Heur.mq1@RSwJxami
NANO-AntivirusRiskware.Win32.Gator.wghx
AvastWin32:Gator-P [PUP]
TencentTrojan.Win32.BitCoinMiner.la
EmsisoftGen:Adware.Heur.mq1@RSwJxami (B)
DrWebAdware.Gator
McAfee-GW-EditionArtemis!PUP
FireEyeGen:Adware.Heur.mq1@RSwJxami
SophosGAIN (PUA)
IkarusAdWare.Win32.Clariagain
GDataGen:Adware.Heur.mq1@RSwJxami
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.6A42C
ViRobotAdware.Gator.1040764
MicrosoftAdware:Win32/Clariagain
ALYacGen:Adware.Heur.mq1@RSwJxami
MalwarebytesMalware.AI.1821723099
FortinetRiskware/Gator
AVGWin32:Gator-P [PUP]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Adware:Win32/Clariagain?

Adware:Win32/Clariagain removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment