Adware

MSIL/Adware.PCMega.H (file analysis)

Malware Removal

The MSIL/Adware.PCMega.H is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Adware.PCMega.H virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine MSIL/Adware.PCMega.H?


File Info:

name: CCE1B5CFA511F321E554.mlw
path: /opt/CAPEv2/storage/binaries/824e6bafafbd964bd7a90c0f26d04062ba2b1c059566db1588dfde775228ceb3
crc32: 1DFDCD18
md5: cce1b5cfa511f321e55456f84d528d6a
sha1: 8dfcd1d307b2e8bce9bc267f287d8f0f3b68bb45
sha256: 824e6bafafbd964bd7a90c0f26d04062ba2b1c059566db1588dfde775228ceb3
sha512: 483beb8b3cd0802d84f16789cd6562bf14add978f1eed5820f63839d77c6925c832e5e63de0374481afed81ab30c3100db2f6c92a3dbca2369353a08b8ce8743
ssdeep: 384:RlFguo6jfzv48odOokQ7MNxQGyv/+uV+R2BYfwnouNeLNek+vD:HsizxNq1+l2BFno
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DFA22935B35C4663D4684AFB4E6356140336F6130819EECE3BC82D8F5EA3F648912B9B
sha3_384: ec47be971fc699ead122158477aa82aa5e627a3477ffa4bb745ef3b81fb19b49dfeae2323ac32d5dc358f9c3772b32ec
ep_bytes: ff250020400000000000000000000000
timestamp: 2013-02-27 18:47:19

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 1.0.0.0
InternalName: PlMrCHWZlRMjTqDuhZMC.exe
LegalCopyright:
OriginalFilename: PlMrCHWZlRMjTqDuhZMC.exe
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Adware.PCMega.H also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 99)
FireEyeGeneric.mg.cce1b5cfa511f321
ALYacGen:Variant.Adware.PCMega.1
CylanceUnsafe
VIPRETrojan.MSIL.Reveton.a (v)
SangforTrojan.Win32.Agent.nil
K7AntiVirusTrojan ( 700000121 )
AlibabaAdWare:MSIL/Midia.cd637394
K7GWTrojan ( 700000121 )
Cybereasonmalicious.fa511f
VirITTrojan.Win32.DownLoader8.UVR
CyrenW32/MSIL_Dloader.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Adware.PCMega.H
APEXMalicious
AvastFileRepMalware [PUP]
Kasperskynot-a-virus:HEUR:AdWare.MSIL.Midia.gen
BitDefenderGen:Variant.Adware.PCMega.1
NANO-AntivirusTrojan.Win32.RiskGen.dcurxx
ViRobotAdware.Pcmega.21504.G
MicroWorld-eScanGen:Variant.Adware.PCMega.1
TencentMsil.Adware.Pcmega.Tdfl
Ad-AwareGen:Variant.Adware.PCMega.1
EmsisoftGen:Variant.Adware.PCMega.1 (B)
ComodoTrojWare.MSIL.TrojanDownloader.Agent.BCG@4veuin
DrWebTrojan.DownLoader8.14083
ZillyaAdware.PCMega.Win32.304
McAfee-GW-EditionPUP-FBB
SophosGeneric PUA IN (PUA)
Paloaltogeneric.ml
GDataGen:Variant.Adware.PCMega.1
JiangminTrojan/Foreign.cnb
WebrootW32.Trojan.Gen
AviraADWARE/Adware.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.12E5E8
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Bladabindi.sa
ArcabitTrojan.Adware.PCMega.1
SUPERAntiSpywareAdware.PCMega
ZoneAlarmnot-a-virus:HEUR:AdWare.MSIL.Midia.gen
MicrosoftBackdoor:Win32/Bladabindi!ml
TACHYONTrojan/W32.DN-Small.21504.AC
AhnLab-V3Win-Trojan/Agent.21504.VQ
BitDefenderThetaGen:NN.ZemsilF.34232.bm0@aeJ66si
MAXmalware (ai score=99)
VBA32Hoax.Foreign
MalwarebytesMalware.AI.3415239725
TrendMicro-HouseCallTROJ_FRS.0NA103BL20
RisingTrojan.Generic/MSIL@AI.91 (RDM.MSIL:uynYfUYQ24kvGvWmY1ZRBQ)
SentinelOneStatic AI – Suspicious PE
FortinetAdware/PCMega
AVGFileRepMalware [PUP]
PandaTrj/Dtcontx.B
MaxSecureTrojan.Malware.300983.susgen

How to remove MSIL/Adware.PCMega.H?

MSIL/Adware.PCMega.H removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment