Adware

SigAdware.PowerSoftwareLimited (file analysis)

Malware Removal

The SigAdware.PowerSoftwareLimited is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What SigAdware.PowerSoftwareLimited virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Harvests cookies for information gathering

How to determine SigAdware.PowerSoftwareLimited?


File Info:

name: 7C816F3B7D9B2AAC0E7A.mlw
path: /opt/CAPEv2/storage/binaries/0b8ef2180c6f17fe0eb27d5d344bb7e1dfb0ae32c17d40fb7f6780656c83203e
crc32: 11CC0D1D
md5: 7c816f3b7d9b2aac0e7a406fdc9d4abe
sha1: cbf0fa4f5ef4c8ef2063ce8f1d8f574ca5ed2d04
sha256: 0b8ef2180c6f17fe0eb27d5d344bb7e1dfb0ae32c17d40fb7f6780656c83203e
sha512: 1ea61388612b074ac50ad6b51d03128e1d8bc4c32f1d67c283726b36f0e12145e1946821ad1e5e024e6a83bed941f3a2f6a6602b05cf59ddea0256574ce46adc
ssdeep: 98304:OmU8cXYgtF3JfQAzm7jFcXRJejdd+A9uSDiz3t:Xy3JfcFcBJCddpuSDc3t
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1631633013FE195B1D27656372D396711293C7D319A28CABEA3981E1ECDB86C2E520F73
sha3_384: 823f1164f2de8f20b37a061024783f45ddbd022301a69667b1764d38e5b8ef8a148068efc5fcc2696fa28606365f273f
ep_bytes: e8ce040000e98efeffff3b0dc8a14300
timestamp: 2018-09-30 18:01:44

Version Info:

0: [No Data]

SigAdware.PowerSoftwareLimited also known as:

BkavW32.AIDetect.malware2
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
SentinelOneStatic AI – Suspicious PE
GridinsoftRansom.Win32.Sabsik.sa
CynetMalicious (score: 100)
McAfeeArtemis!7C816F3B7D9B
VBA32SigAdware.PowerSoftwareLimited
APEXMalicious
eGambitUnsafe.AI_Score_99%

How to remove SigAdware.PowerSoftwareLimited?

SigAdware.PowerSoftwareLimited removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment