Trojan

Trojan:Win32/Adclicker.AN malicious file

Malware Removal

The Trojan:Win32/Adclicker.AN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Adclicker.AN virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan:Win32/Adclicker.AN?


File Info:

name: A73C911C7947F5EB9AD1.mlw
path: /opt/CAPEv2/storage/binaries/1a828a7c95cb5ec71d4318818bbb1740c9364424ded598165146ed7f07bc936a
crc32: 8A63D31C
md5: a73c911c7947f5eb9ad1c6912505864f
sha1: dd659132f4d8ea5a5b9df2a6dbea268abf25009b
sha256: 1a828a7c95cb5ec71d4318818bbb1740c9364424ded598165146ed7f07bc936a
sha512: 4edae333ec5d67111598929cdb97e4b21482cc9fbf10dfaf1b7fe0b900152811898183710d9ed0067ef110571872d7407286c27c8a0151e979310caf061a9aed
ssdeep: 12288:mvyhruWJYs8K01Ww+aACvLVGwwrubk41J5iMA62s:IyrQew+af00b12v
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T173C4C1FDE1254B17E192E3BAF6A46245182C34D6002C265FFC3D6BEC24DC4DAED64E98
sha3_384: c8bd56f337dc838cdc254fc699aafec0b6562c068832196dedd131259e62855b466e1401a016733a95467e3d5963a3e0
ep_bytes: 807c2408010f85b901000060be00c003
timestamp: 2011-12-15 18:13:08

Version Info:

FileDescription: Ultra Chat Agent 2007
FileVersion: 9.16.0.0
OriginalFilename: chaagent.dll
ProductName: Ultra Chat Agent 2007
LegalCopyright: Copyright (c) CHAgent Company
Translation: 0x0409 0x04e4

Trojan:Win32/Adclicker.AN also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.OnLineGames.d!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.a73c911c7947f5eb
SkyhighBehavesLike.Win32.Worm.ht
McAfeeArtemis!A73C911C7947
Cylanceunsafe
ZillyaTrojan.OnLineGames.Win32.175779
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/OnLineGames.8e7429fa
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Barys.D4029
BitDefenderThetaGen:NN.ZedlaF.36744.Im@@amS25si
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
APEXMalicious
KasperskyTrojan-GameThief.Win32.OnLineGames.amdh
BitDefenderGen:Variant.Barys.16425
NANO-AntivirusTrojan.Win32.OnLineGames.bnuoym
MicroWorld-eScanGen:Variant.Barys.16425
AvastWin32:Malware-gen
TencentWin32.Trojan-GameThief.Onlinegames.Vmhl
TACHYONTrojan-PWS/W32.WebGame.570831
EmsisoftGen:Variant.Barys.16425 (B)
F-SecureHeuristic.HEUR/AGEN.1300251
DrWebTrojan.MulDrop2.54093
VIPREGen:Variant.Barys.16425
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan/PSW.OnLineGames.cssi
AviraHEUR/AGEN.1300251
Antiy-AVLTrojan[GameThief]/Win32.OnLineGames
KingsoftWin32.Troj.Undef.a
XcitiumMalware@#11b2vyx493531
MicrosoftTrojan:Win32/Adclicker.AN
ZoneAlarmTrojan-GameThief.Win32.OnLineGames.amdh
GDataGen:Variant.Barys.16425
GoogleDetected
VBA32TrojanPSW.OnLineGames.a
ALYacGen:Variant.Barys.16425
MAXmalware (ai score=99)
PandaTrj/CI.A
RisingTrojan.Adclicker!8.351 (CLOUD)
YandexTrojan.GenAsa!uLOIj9kbduc
IkarusExploit.Win32.Senglot
FortinetW32/Onlinegames.AMDH!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Adclicker.AN?

Trojan:Win32/Adclicker.AN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment