Adware

About “Win32/Adware.GoRedir.A” infection

Malware Removal

The Win32/Adware.GoRedir.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.GoRedir.A virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/Adware.GoRedir.A?


File Info:

name: 80FB696EB9DF3F0A66EB.mlw
path: /opt/CAPEv2/storage/binaries/3d8a931b5b3e1d2095273371dd12c7a81a60da92d0ee3ff06772bb5e7cc341d4
crc32: 04F328E4
md5: 80fb696eb9df3f0a66eb424f7752985b
sha1: 0cd5726119b31385113c77ead96d9ccb1fb28fcb
sha256: 3d8a931b5b3e1d2095273371dd12c7a81a60da92d0ee3ff06772bb5e7cc341d4
sha512: 58fd92b0cc6dbf00fefba61bcf0bd33dfd562b3f1548fdb246e8baad55d42d29c7dda77be6c1be741276c44f6a37b79ebb7eb2683b0ee8b98a87f3131ccbb360
ssdeep: 1536:7kUgJ+DOTC2tOmXbJVaK3R0XMJ33iU5hVXl7NeLZ61due6moMNNlltdgHXTzHrzD:obTOubqoNNfoF
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1C1D35B30A5D352EEF3A1E5B446F14F3767BDDD904DE15C0F6F222AAA0B327609935205
sha3_384: 8d5323eba8a465347ffbb49589aad1658fbc64fa214c3c6a56856c1be159c770765ebcd42b494c987c9f37f8d4dd95a5
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2012-05-27 14:36:59

Version Info:

0: [No Data]

Win32/Adware.GoRedir.A also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lIEa
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.80fb696eb9df3f0a
CAT-QuickHealTrojan.Generic.19541
SkyhighBehavesLike.Win32.Dropper.cz
McAfeePUP-XER-WX
Cylanceunsafe
ZillyaAdware.GoRedir.Win32.3931
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/grayware_confidence_90% (W)
AlibabaAdWare:Win32/GoRedir.f396df1d
BaiduWin32.Adware.Generic.e
VirITTrojan.Win32.Siggen4.XJU
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.GoRedir.A
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Adware.Heur.ii7@NGYCJLn
NANO-AntivirusTrojan.Win32.TrjGen.vpgrf
MicroWorld-eScanGen:Adware.Heur.ii7@NGYCJLn
AvastWin32:Agent-AOVF [Adw]
TACHYONTrojan/W32.Agent.131072.DPQ
EmsisoftGen:Adware.Heur.ii7@NGYCJLn (B)
F-SecureAdware.ADWARE/Agent.6021
DrWebTrojan.Siggen4.15802
VIPREGen:Adware.Heur.ii7@NGYCJLn
TrendMicroTSPY_AGENT_CF100237.RDXN
Trapminesuspicious.low.ml.score
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.ahepu
WebrootW32.Trojan.Gen
GoogleDetected
AviraADWARE/Agent.6021
Antiy-AVLTrojan[Backdoor]/Win32.VB
KingsoftWin32.Trojan.Generic.a
MicrosoftProgram:Win32/Wacapew.C!ml
XcitiumApplication.Win32.Adware.Redir.AA@4qzgf1
ArcabitAdware.Heur.EBCDF7
ViRobotBackdoor.Win32.A.VB.131072.K
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Adware.Heur.ii7@NGYCJLn
VaristW32/Agent.PW.gen!Eldorado
AhnLab-V3Trojan/Win32.Jorik.R31767
VBA32Adware.Presenoker
ALYacGen:Adware.Heur.ii7@NGYCJLn
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_AGENT_CF100237.RDXN
RisingTrojan.Generic@AI.100 (RDMK:3uclh1mB3HaYr0K6D1x03Q)
YandexTrojan.GenAsa!FpWXQ/yr/oE
IkarusAdWare.Heur
MaxSecureTrojan.Malware.7164915.susgen
FortinetAdware/GoRedir
BitDefenderThetaGen:NN.ZedlaF.36802.ii7@aGYCJLn
AVGWin32:Agent-AOVF [Adw]
DeepInstinctMALICIOUS

How to remove Win32/Adware.GoRedir.A?

Win32/Adware.GoRedir.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment