Adware

How to remove “Adware:Win32/Stapcore”?

Malware Removal

The Adware:Win32/Stapcore is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware:Win32/Stapcore virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Uses Windows utilities for basic functionality
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode get eip malware family
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Accessed credential storage registry keys
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Collects information to fingerprint the system
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Adware:Win32/Stapcore?


File Info:

name: 43287AB881F2F0E81BFA.mlw
path: /opt/CAPEv2/storage/binaries/869e1d7509aa8be69a6532098eb75b9ba86f9cc40e93f207f33bb0ea15707020
crc32: 53AFC658
md5: 43287ab881f2f0e81bfae1009bd918d1
sha1: 904a996f33aca87bbc57a9f9b7e0102b01cd3c6c
sha256: 869e1d7509aa8be69a6532098eb75b9ba86f9cc40e93f207f33bb0ea15707020
sha512: b0567fc192a199d0eccc83a8116da6d69086cb6e4ea1fa0d06b72e414c4389ea2d072913a60d85892b34a26c33d217bae290ffee22a5072c8d6f9028db796d1b
ssdeep: 3072:RbG7N2kDTHUpou2eDGBPzy5n+dmEmGCKy:RbE/HUJ6ry5n+3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T159C3BE10B3649466F4A3CB312578623A4A79AC11F5904B8F3FD05B5839EE3B19F2E3E5
sha3_384: 800555ba40209093deecd19f842c8b24cf4c0ef4e008de13ef36d60e5e55c3011cdaa62c0cdab7eaa508ec41888f4ff3
ep_bytes: 558bec81ecf40300005356576a205f33
timestamp: 2021-09-25 21:57:46

Version Info:

CompanyName: Fast Corporation Ltd.
FileDescription: Setup
LegalCopyright: All rights reserved 2024
ProductName: Get Fast
ProductVersion: 2.3.3.7
Translation: 0x0409 0x04e4

Adware:Win32/Stapcore also known as:

Elasticmalicious (high confidence)
SkyhighArtemis
McAfeeArtemis!43287AB881F2
Cylanceunsafe
ZillyaAdware.PCAppStore.Win32.436
SangforAdware.Win32.Veryfast.Vkmm
AlibabaAdWare:Win32/PCAppStore.02e4b707
SymantecPUA.Gen.2
ESET-NOD32Win32/Adware.VeryFast.M
TrendMicro-HouseCallTROJ_GEN.R002H07DM24
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.Win32.PCAppStore.gen
AvastNSIS:AdwareX-gen [Adw]
TencentWin32.Trojan.FalseSign.Kajl
DrWebProgram.Unwanted.5478
SophosFast App Installer (PUA)
GoogleDetected
VaristW32/ABAdware.NKBB-2465
MicrosoftAdware:Win32/Stapcore
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.PCAppStore.gen
GDataWin32.Application.Agent.EPIJZV
MalwarebytesPUP.Optional.VeryFast.DDS
AVGNSIS:AdwareX-gen [Adw]
DeepInstinctMALICIOUS

How to remove Adware:Win32/Stapcore?

Adware:Win32/Stapcore removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment