Adware

Dropped:Adware.WinFixer.AB removal tips

Malware Removal

The Dropped:Adware.WinFixer.AB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Adware.WinFixer.AB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Creates a registry key or value with NUL characters to avoid detection with regedit
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Checks the version of Bios, possibly for anti-virtualization
  • Anomalous binary characteristics

How to determine Dropped:Adware.WinFixer.AB?


File Info:

crc32: 4868289D
md5: 7706f017cee00b4079850c2254243e18
name: 7706F017CEE00B4079850C2254243E18.mlw
sha1: 0236c4dfb7877c5f9f62d36ea8dc89fd7d20c4eb
sha256: 329fc8cbcd8d70859fe95bbf7c1d045ccec81502fcf994aef432482bf0149ed2
sha512: 5ceb2ab63bee2c35e477fa4f005876d2244db4f2b36088e72e9b5233d5de9502f389bccd017f74ae5976041e70ac6e9812bb924772e5379f5d2a12018965b975
ssdeep: 49152:jvsMeyxsMRAoTFLPsOauRWXIcrRx+8hKu691zt5e:rRAohLPsOFYX/ot5e
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

0: [No Data]

Dropped:Adware.WinFixer.AB also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.WinFixer.c!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Gamania.40877
ClamAVWin.Malware.Npop-9759126-0
ALYacDropped:Adware.WinFixer.AB
CylanceUnsafe
ZillyaTrojan.WinFixer.Win32.10
SangforTrojan.Win32.SchoolGirl.dmd
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderDropped:Adware.WinFixer.AB
Cybereasonmalicious.7cee00
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Adware.WinFixer
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-FakeAV.Win32.WinFixer.f
NANO-AntivirusTrojan.Win32.Gamania.fbstba
MicroWorld-eScanDropped:Adware.WinFixer.AB
Ad-AwareDropped:Adware.WinFixer.AB
SophosGeneric ML PUA (PUA)
ComodoPacked.Win32.MPEC.Gen@2oey7k
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.7706f017cee00b40
EmsisoftDropped:Adware.WinFixer.AB (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Small.tle
AviraTR/Dropper.Gen
eGambitGeneric.Malware
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitAdware.WinFixer.AB
GDataDropped:Adware.WinFixer.AB
McAfeeArtemis!7706F017CEE0
MAXmalware (ai score=63)
VBA32TrojanFakeAV.WinFixer
PandaTrj/CI.A
IkarusTrojan-Dropper.Agent
FortinetPossibleThreat

How to remove Dropped:Adware.WinFixer.AB?

Dropped:Adware.WinFixer.AB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment