Adware

Win32/Adware.Hebchengjiu.A removal

Malware Removal

The Win32/Adware.Hebchengjiu.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.Hebchengjiu.A virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Queries information on disks, possibly for anti-virtualization
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Network activity contains more than one unique useragent.
  • A process sent information about the computer to a remote location.
  • Collects information about installed applications
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Creates a copy of itself
  • Harvests cookies for information gathering

How to determine Win32/Adware.Hebchengjiu.A?


File Info:

name: 57E17B0003EB5C4914BE.mlw
path: /opt/CAPEv2/storage/binaries/e9374b184336de2591f98800b2b5349d65800e523aee958531e36a051ae59d33
crc32: 5C3758D2
md5: 57e17b0003eb5c4914be4b9b3fb050ce
sha1: 1ee842067eca8ba4d792552d5acd162620e2d85c
sha256: e9374b184336de2591f98800b2b5349d65800e523aee958531e36a051ae59d33
sha512: 9e546dc05d6d711499d4a8fbce358d52e36da643552635096fea269077ef4db4844e88575f0a5b1b897a3ffd32b3fdfd786d56a05f844b82839571b672f7da77
ssdeep: 24576:X6g3coT7PnM4/WunIK82ssIm/XpNtYD62tO1YPE/tzaSM15zRU5PrNZHUdXxCfn:X3FnCsIiHtY3tM/tmS+5zRmT0dBCfn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T190A59D43F19290F1D21100701AF6633A9AB9FA760D359BA7DB91CEF85D312E1DA2731E
sha3_384: 8fb6b6d43762edbf6295d10859de6f825651c5493c828cc65709f42e28cc3eee0fe47a68dd9d47dfbd0723cd5b5c02fb
ep_bytes: e84a750000e9000000006a1468004060
timestamp: 2016-08-19 07:48:04

Version Info:

FileVersion: 6.1.0.1
FileDescription:
ProductName:
ProductVersion: 6.1.0.1
CompanyName:
LegalCopyright:
Comments: 本程序使用易语言编写(http://www.dywt.com.cn)
Translation: 0x0804 0x04b0

Win32/Adware.Hebchengjiu.A also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Dinwod.mgDt
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.8131
FireEyeGeneric.mg.57e17b0003eb5c49
McAfeeGenericRXAA-AA!57E17B0003EB
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 004f4efb1 )
AlibabaMalware:Win32/km_2c602d1.None
K7GWAdware ( 004f4efb1 )
Cybereasonmalicious.003eb5
CyrenW32/S-a0341806!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Hebchengjiu.A
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Mikey-6718286-0
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderGen:Variant.Doina.8131
NANO-AntivirusRiskware.Win32.FlyStudio.eghjor
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.10b241d3
Ad-AwareGen:Variant.Doina.8131
EmsisoftGen:Variant.Doina.8131 (B)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
DrWebTrojan.DownLoader23.31915
ZillyaAdware.Kqheb.Win32.2
TrendMicroTROJ_GEN.R002C0OL521
McAfee-GW-EditionBehavesLike.Win32.PUPXFM.vh
SophosGeneric PUA BO (PUA)
IkarusTrojan.Win32.Tonmye
GDataWin32.Application.PUPStudio.B
JiangminAdWare.Kqheb.f
AviraADWARE/Hebchengjiu.itpst
Antiy-AVLTrojan/Generic.ASCommon.FA
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZexaF.34084.jw1@aG6ZZkpb
ALYacGen:Variant.Doina.8131
MAXmalware (ai score=86)
VBA32BScope.Trojan.Downloader
MalwarebytesTrojan.MalPack.FlyStudio
TrendMicro-HouseCallTROJ_GEN.R002C0OL521
RisingTrojan.ClickDouTu!1.A668 (CLASSIC)
YandexTrojan.GenAsa!ejD1bcuz2wg
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetRiskware/Hebchengjiu
AVGWin32:Adware-gen [Adw]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Win32/Adware.Hebchengjiu.A?

Win32/Adware.Hebchengjiu.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment