PUA

AdWin (PUA) removal tips

Malware Removal

The AdWin (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWin (PUA) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine AdWin (PUA)?


File Info:

name: C6E3D6485F4F960AC6B0.mlw
path: /opt/CAPEv2/storage/binaries/d48d16bec76afede610fd96ec3420e24e01fc82b3a2568f602abe0cb990322f3
crc32: 6774BC1F
md5: c6e3d6485f4f960ac6b08f0ec6d498c3
sha1: 08cb0aa5b64279d6423b4679a3aee0cc46799478
sha256: d48d16bec76afede610fd96ec3420e24e01fc82b3a2568f602abe0cb990322f3
sha512: a566c06fe3b9d9743f832979ee63f6b63fd86ff2ca80fcde86f291ecb3b8af5721d139465a23173445529b9c7f8ebcd2bab9873919d68818729100261a608d7f
ssdeep: 12288:KSADDHyj7/BbmaDEPoiAtPA6lHu1PUK1FpYScTbNNwIwBJwBarsGSjF:Uy9EAZI6lK1FpaTBKIGJGayF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B4056B51B481C034F9BD01BC02E99777262B6A225716D6E377AC5D0A3B201FE7EF4A36
sha3_384: 70c60d90606d7d5fa0f13660e9b723d00b8cd3a2c6c0568f4a4d0a13c7dc87f0803103a5dcd467b7ae54141f29f3d3f6
ep_bytes: e8a7d10000e9000000006a1468b85348
timestamp: 1970-01-01 00:01:23

Version Info:

FileVersion: 1.5.6.2919
ProductVersion: 15, 6.29
Translation: 0x0804 0x04b0

AdWin (PUA) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.306696
CAT-QuickHealTrojan.Skeeyah.17537
ALYacGen:Variant.Zusy.306696
CylanceUnsafe
VIPREGen:Variant.Zusy.306696
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 004c75cb1 )
K7GWAdware ( 004c75cb1 )
Cybereasonmalicious.85f4f9
BaiduWin32.Trojan.Agent.aau
VirITTrojan.Win32.Generic.BWKL
CyrenW32/Horst.A.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Adware.BHO.NLN
APEXMalicious
ClamAVWin.Malware.Jaik-9660700-0
KasperskyTrojan.Win32.Agent.iguu
BitDefenderGen:Variant.Zusy.306696
NANO-AntivirusTrojan.Win32.Crypted.dtlasb
AvastWin32:GenMaliciousA-QKI [Trj]
TencentMalware.Win32.Gencirc.10b08034
Ad-AwareGen:Variant.Zusy.306696
SophosAdWin (PUA)
ComodoApplication.Win32.AdWare.BHO.AD@5t6i8s
DrWebTrojan.Siggen6.45515
ZillyaAdware.BHO.Win32.7751
McAfee-GW-EditionBehavesLike.Win32.Ransomware.ch
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.c6e3d6485f4f960a
EmsisoftGen:Variant.Zusy.306696 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Zusy.306696
JiangminTrojan/Agentb.bpk
AviraTR/Kryptik.qgmpa
Antiy-AVLTrojan/Generic.ASMalwS.3E79
KingsoftWin32.Heur.KVM007.a.(kcloud)
ArcabitTrojan.Zusy.D4AE08
MicrosoftTrojan:Win32/Dorv.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.OnLineGames.R156869
McAfeeTrojan-FHGH!C6E3D6485F4F
MAXmalware (ai score=80)
VBA32BScope.Trojan.KillFiles
MalwarebytesPUP.Optional.ChinAd
RisingAdWare.Win32.BHO.fkg (CLASSIC)
YandexTrojan.GenAsa!ZfO/u3lZgK0
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.IGUU!tr
BitDefenderThetaGen:NN.ZexaF.34806.Yq0@aGX9XQfj
AVGWin32:GenMaliciousA-QKI [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove AdWin (PUA)?

AdWin (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment