Adware

How to remove “Win32/Adware.Agent.NPP”?

Malware Removal

The Win32/Adware.Agent.NPP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.Agent.NPP virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Adware.Agent.NPP?


File Info:

name: 838CC5C026480397DE0B.mlw
path: /opt/CAPEv2/storage/binaries/8b0adaaac984d45fb394775ce5f6e3f27b2624a642764c5d5a80d180c88c95e6
crc32: 91C25FC7
md5: 838cc5c026480397de0bacd7ec2a363d
sha1: a5ef5f1b82e5ca3bb041dacdab70f5c4a251f0e0
sha256: 8b0adaaac984d45fb394775ce5f6e3f27b2624a642764c5d5a80d180c88c95e6
sha512: 03f7658aedaba11359a15017f5a315bc24ebf411ebf018ed5d45f764fcafb3efa123c35ecf05827b082a38d4cb6bd45637cf0445e6ad3f8f20e5d9207c72a95f
ssdeep: 49152:fpBMBT6WEO2MFV6svprw+bNmWvoJ4uL+CnoadzLmmRXKXGdXcfhs:fpWBTSCV50+bZQJ4uL+ZaLvXes
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T137D533BEBE109F6DD8E94A3017FA122AB8AED5C05257100F1B7A637732758D3A44CC9D
sha3_384: 5d2379487258400e56b31e5c0373eeec6a1008787998053980b02a2fdaa4f5b94bbab07d047c0150fa83130501276c61
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-04-30 14:07:33

Version Info:

CompanyName: www.paopaoche.net
FileDescription: 皇家战争中文版
FileVersion: 中文版
LegalCopyright: Copyright paopaoche.Net 2014 All Rights Reserved
ProductName: 皇家战争中文版
ProductVersion: 中文版
Translation: 0x0804 0x03a8

Win32/Adware.Agent.NPP also known as:

BkavW32.AIDetectMalware
LionicRiskware.Win32.Generic.1!c
DrWebTrojan.PWS.Banker1.25346
McAfeeArtemis!838CC5C02648
MalwarebytesGeneric.Malware.AI.DDS
SangforAdware.Win32.Agent.Vh1h
AlibabaAdWare:Win32/Generic.c4792553
CrowdStrikewin/grayware_confidence_90% (W)
CyrenW32/Trojan.FVHH-7793
Elasticmalicious (high confidence)
ESET-NOD32Win32/Adware.Agent.NPP
ClamAVWin.Downloader.84425-1
NANO-AntivirusTrojan.Win32.Mlw.efvjiu
RisingAdware.StartPage!1.DC11 (CLOUD)
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
SophosGeneric Reputation PUA (PUA)
GoogleDetected
Antiy-AVLGrayWare/Win32.Paopaoche
XcitiumApplication.Win32.MeinV.AK@57p4lw
MicrosoftPUA:Win32/Paopaoche
CynetMalicious (score: 100)
VBA32TrojanDropper.Agent
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R023H06GB23
FortinetAdware/Agent
DeepInstinctMALICIOUS

How to remove Win32/Adware.Agent.NPP?

Win32/Adware.Agent.NPP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment