Adware

NSIS:Adware-DR [Adw] (file analysis)

Malware Removal

The NSIS:Adware-DR [Adw] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS:Adware-DR [Adw] virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

Related domains:

wpad.local-net
track.bndle.com
cdn01.bcdn.info

How to determine NSIS:Adware-DR [Adw]?


File Info:

name: 9382DCFA84F728DDCBD5.mlw
path: /opt/CAPEv2/storage/binaries/123921c0a250377f62a009935d94b3d1325e0fdb22a441be426b06ecd884d192
crc32: B49362ED
md5: 9382dcfa84f728ddcbd57626e20f4140
sha1: 7c4fd80bf28a11b66c4f36a017c13378afe042f6
sha256: 123921c0a250377f62a009935d94b3d1325e0fdb22a441be426b06ecd884d192
sha512: 2c65da3e6d1a136948282442d5956e1bf3109c563720f1ea53dbff58775325f1aa01aa0624e123dbeb2a8a00319eae6a7a0f3c201f3d03389296da8b8dcb7bdb
ssdeep: 12288:x6yRG6QiGtCnKNMIcvNrSQ45pXscbIWwor68e0:cyz5wJMfNSQ45pXscbGo6s
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11EA4227C61D9C563CA71FB3241FE5332DBB56E492A5021DB8B72BFE58831086DF221A4
sha3_384: 8badfdb598c727a49914a0c8bb623813211cb346b16d4d54695d73d78d43476acb9a8795f3a33d323ff3077127b14477
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:46

Version Info:

Comments: vGrabber setup
CompanyName: http://vgrabber.org
FileDescription: vGrabber setup
FileVersion: 1.14
LegalCopyright: © http://vgrabber.org (vGrabberWR_C48US_Single_Conduit)
ProductName: vGrabber
Translation: 0x0409 0x0000

NSIS:Adware-DR [Adw] also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanAdware.GenericKD.38128797
FireEyeAdware.GenericKD.38128797
ALYacAdware.GenericKD.38128797
CylanceUnsafe
VIPREBundlore (fs)
K7AntiVirusTrojan-Downloader ( 00473e581 )
AlibabaTrojanDownloader:Win32/Ezula.66c4dd2a
K7GWTrojan-Downloader ( 00473e581 )
ESET-NOD32multiple detections
APEXMalicious
Kasperskynot-a-virus:HEUR:Downloader.Win32.Agent.gen
BitDefenderAdware.GenericKD.38128797
NANO-AntivirusRiskware.Nsis.Adw.dorcdr
SUPERAntiSpywarePUP.InstallCore/Variant
AvastNSIS:Adware-DR [Adw]
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareAdware.GenericKD.38128797
SophosvGrabber (PUA)
ComodoMalware@#3ppjlm5v07rvo
DrWebAdware.Downware.113
TrendMicroTROJ_GEN.R002C0PKQ21
McAfee-GW-EditionBehavesLike.Win32.Downloader.gc
EmsisoftAdware.GenericKD.38128797 (B)
SentinelOneStatic AI – Suspicious PE
GDataAdware.GenericKD.38128797
WebrootW32.Adware.Vgrabber
Antiy-AVLTrojan/Generic.ASMalwNS.BA4
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftProgram:Win32/Wacapew.C!ml
CynetMalicious (score: 100)
McAfeeGeneric PUP.jy
VBA32suspected of Trojan.Downloader.gen
MalwarebytesPUP.Optional.BundleInstaller.VG
TrendMicro-HouseCallTROJ_GEN.R002C0PKQ21
FortinetRiskware/Bundlore
AVGNSIS:Adware-DR [Adw]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_60% (D)

How to remove NSIS:Adware-DR [Adw]?

NSIS:Adware-DR [Adw] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment