Adware

Should I remove “Win32/Adware.ConvertAd.ADY”?

Malware Removal

The Win32/Adware.ConvertAd.ADY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.ConvertAd.ADY virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Win32/Adware.ConvertAd.ADY?


File Info:

name: 838A0E4A89B61EE802B0.mlw
path: /opt/CAPEv2/storage/binaries/ce5336cc145b8ea2d65e9904118ae1a0e3001368be631d277806e4d5c5603b1b
crc32: 2168931D
md5: 838a0e4a89b61ee802b0ee03e8175c3d
sha1: 6e7167d17e319f5fab913222ea4cb45802d7a17b
sha256: ce5336cc145b8ea2d65e9904118ae1a0e3001368be631d277806e4d5c5603b1b
sha512: 35e4b4ebdbbb3543ac4b3dc0b37386c696a3d00a2f6d155d58db074f6fe1b664bff29201461e47a4b7c570a9e5f032f06453ee4348b71a1a83ca787a06b64ceb
ssdeep: 6144:yskh3TLBNOc5dfMRFRyNiMR0vn071Hywk8Dt4zZZj/k8F:2h3TLBNP5dcI90gNtyzZZj/kO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B154122554EA88BBC81202BD4633A726F6F677131921EE0B6B501F6F96707C7DD031D9
sha3_384: 677fabfb5f2ab778af4da9d649604759f08f3e42af4af471c88f1adf282c16a59f9806b12f7a998fc7edeef99ba26024
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:46

Version Info:

0: [No Data]

Win32/Adware.ConvertAd.ADY also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.Vopak.2!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.838a0e4a89b61ee8
McAfeeArtemis!838A0E4A89B6
K7AntiVirusAdware ( 004d96ff1 )
AlibabaAdWare:Win32/Vopak.ab6cfefe
CrowdStrikewin/malicious_confidence_90% (D)
BaiduMulti.Threats.InArchive
CyrenW32/Agent.CXX.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Adware.ConvertAd.ADY.gen
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:AdWare.Win32.Vopak.aiks
AvastNSIS:ConvertAd-W [Adw]
TencentWin32.Adware.Vopak.Dztq
DrWebAdware.ConvertAd.94
VIPREAdware.Win32.Vopak
McAfee-GW-EditionBehavesLike.Win32.AdwareAdload.dc
SophosGeneric PUA GO (PUA)
SentinelOneStatic AI – Malicious PE
WebrootW32.Adware.Somoto
AviraHEUR/AGEN.1124627
ViRobotAdware.Convertad.283947
MicrosoftTrojan:Win32/Wacatac.A!ml
CynetMalicious (score: 100)
VBA32AdWare.Vopak
TrendMicro-HouseCallTROJ_GEN.R002H0CL321
AVGNSIS:ConvertAd-W [Adw]
Cybereasonmalicious.17e319

How to remove Win32/Adware.ConvertAd.ADY?

Win32/Adware.ConvertAd.ADY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment