Adware

About “Win32/Adware.GoRedir.A” infection

Malware Removal

The Win32/Adware.GoRedir.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.GoRedir.A virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/Adware.GoRedir.A?


File Info:

name: C324EED435E3F627CA3F.mlw
path: /opt/CAPEv2/storage/binaries/09f7bf0a76ce02fb3a0770bcee7120203478b81cf4cb205b4ee4286145f94093
crc32: 1DFFA2E9
md5: c324eed435e3f627ca3f31c960d3c5fa
sha1: 2d72a674a412c124f84e7432836ba62b42fd095f
sha256: 09f7bf0a76ce02fb3a0770bcee7120203478b81cf4cb205b4ee4286145f94093
sha512: b88492443fc02bc222b44ec5c3a7f52f98ed66b231670f796ca07dbf0c1baaff30f5c7d7d747ca5786f98536af49b1db0888c7935d32aca5b4b54d3467d31676
ssdeep: 768:04Rs4+D7YY2uXZ9hAVagyStKIZ+2fJcwqVETAz4HMBbsjjRGPZMoudB0vE7V:LsUY2IGS7IZ+nVETAzFs1fouB0vo
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T10CD48D39B9DA86FAF385E07902F40FDB27FDDD8046E08D0F6B6726F90D22251953A241
sha3_384: 201a7ac62637378651c5c70a8698dcc0d225d398262b097b3076ed6bc6999db208f55131848973ff049867995205a468
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2012-03-18 08:08:14

Version Info:

0: [No Data]

Win32/Adware.GoRedir.A also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lIEa
AVGWin32:Adware-ACU [Adw]
MicroWorld-eScanGen:Adware.Heur.Ki7@NC6OsRh
FireEyeGeneric.mg.c324eed435e3f627
CAT-QuickHealTrojan.Generic.19475
SkyhighBehavesLike.Win32.Infected.hz
McAfeePUP-XFC-MM
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
AlibabaAdWare:Win32/GoRedir.0a3b5f86
BitDefenderThetaGen:NN.ZedlaF.36802.Ki7@aC6OsRh
VirITTrojan.Win32.Siggen4.XLD
SymantecSMG.Heur!gen
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Adware.GoRedir.A
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Agent-36925
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Adware.Heur.Ki7@NC6OsRh
NANO-AntivirusTrojan.Win32.TrjGen.csswyz
AvastWin32:Adware-ACU [Adw]
RisingTrojan.Generic@AI.100 (RDMK:UpGsT2z2SNUZvkZCnLXUNA)
EmsisoftGen:Adware.Heur.Ki7@NC6OsRh (B)
BaiduWin32.Adware.Generic.e
F-SecureAdware.ADWARE/Agent.6021
DrWebTrojan.Siggen4.15837
ZillyaAdware.GoRedir.Win32.832
TrendMicroTSPY_GOREDIR_BK0802A4.TOMC
Trapminesuspicious.low.ml.score
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.aherb
VaristW32/Agent.PW.gen!Eldorado
AviraADWARE/Agent.6021
MAXmalware (ai score=99)
Antiy-AVLTrojan/Win32.Unknown
KingsoftWin32.Trojan.Generic.a
MicrosoftProgram:Win32/Wacapew.C!ml
XcitiumApplication.Win32.Adware.Redir.AA@4qzgf1
ArcabitAdware.Heur.EDB3B3
ViRobotBackdoor.Win32.A.VB.602112.A
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Adware.Heur.Ki7@NC6OsRh
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R31767
Acronissuspicious
ALYacGen:Adware.Heur.Ki7@NC6OsRh
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_GOREDIR_BK0802A4.TOMC
TencentAdware.Win32.Agent.eev
YandexTrojan.GenAsa!FpWXQ/yr/oE
IkarusAdWare.Heur
MaxSecureTrojan.Malware.121218.susgen
FortinetRiskware/GoRedir
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/BHO.AZ

How to remove Win32/Adware.GoRedir.A?

Win32/Adware.GoRedir.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment