Malware

Win32/AdClicker.NBD information

Malware Removal

The Win32/AdClicker.NBD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/AdClicker.NBD virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

adf.ly
aporasal.net
cdn.adf.ly
ocsp.digicert.com

How to determine Win32/AdClicker.NBD?


File Info:

crc32: 62A7579E
md5: 41d16e3a7a2b282bc01493210355884e
name: 41D16E3A7A2B282BC01493210355884E.mlw
sha1: 00b2be507168292d97cdeed66805644a276732ff
sha256: aca2bb13149439b4faefce5dfb14ed5db68164de108a44606dc0f5ac8e5e79cc
sha512: d6983bce2413fe8e211f1d42e007b1e31d3974ec7f4306a12bee108ecd12f13c638b79d384558114a20b7fa80752575c1fe714b081ddcfdf21d1880fb3073370
ssdeep: 12288:jZYze8SQ8m9WrwedAFQICi00/8h4EKKRACbsNVWmlAgXClVwXV++0HcFD/:9YawBneeFQp0/8VKKKemlAC+1HcFD
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: weq
InternalName: MouseModz 6131
FileVersion: 1.00.0272
CompanyName: mouse
LegalTrademarks: wqewqq
Comments: mouse
ProductName: qwe
ProductVersion: 1.00.0272
FileDescription: qwe
OriginalFilename: MouseModz 6131.exe

Win32/AdClicker.NBD also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Strictor.255055
McAfeeArtemis!41D16E3A7A2B
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 004e3db21 )
BitDefenderGen:Variant.Strictor.255055
K7GWTrojan ( 004e3db21 )
ArcabitTrojan.Strictor.D3E44F
CyrenW32/A-5e0fec9b!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyWorm.Win32.Feebs.pgs
NANO-AntivirusTrojan.Win32.Inject.byguqp
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Strictor.255055
EmsisoftGen:Variant.Strictor.255055 (B)
ComodoMalware@#1d7so4bxhzntl
F-SecureTrojan.TR/Crypt.PEPM.Gen
DrWebTrojan.Click3.26976
VIPRETrojan.Win32.Generic!BT
TrendMicroCryp_Xed-12
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGen:Variant.Strictor.255055
SophosML/PE-A
WebrootPua.Gen
AviraTR/Crypt.PEPM.Gen
eGambitUnsafe.AI_Score_54%
MAXmalware (ai score=82)
Antiy-AVLTrojan[GameThief]/Win32.WOW.gic
KingsoftWin32.HackTool.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
SUPERAntiSpywareTrojan.Agent/Gen-Patcher
ZoneAlarmWorm.Win32.Feebs.pgs
GDataGen:Variant.Strictor.255055
CynetMalicious (score: 100)
ALYacGen:Variant.Strictor.255055
VBA32BScope.Worm.Feebs
MalwarebytesMalware.Heuristic.1001
ESET-NOD32a variant of Win32/AdClicker.NBD
TrendMicro-HouseCallCryp_Xed-12
TencentWin32.Worm.Feebs.Pdcj
IkarusTrojan.Injector
FortinetMalware_fam.NB
BitDefenderThetaGen:NN.ZevbaF.34804.Oi0faC2wfidi
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
Qihoo-360Win32/Worm.755

How to remove Win32/AdClicker.NBD?

Win32/AdClicker.NBD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment