Adware

Win32/Adware.InternetAntivirus removal instruction

Malware Removal

The Win32/Adware.InternetAntivirus is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.InternetAntivirus virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/Adware.InternetAntivirus?


File Info:

name: C1FC783F4E947B715F4D.mlw
path: /opt/CAPEv2/storage/binaries/202e55f35dc92ccda5dfdb61c78113e163dd1426976d902957f9f4e290dc2918
crc32: FA1168C5
md5: c1fc783f4e947b715f4dd351dbc4eb0d
sha1: a26c4831e134aaf5df571bfa519b443b51d84861
sha256: 202e55f35dc92ccda5dfdb61c78113e163dd1426976d902957f9f4e290dc2918
sha512: bb7d7646eda496df3116219c48eb6186aa65ad52cd151f8d1b01450cdd7cbf148f244d9d0c13965b977d74914288bd864f948f01e3d03d17430c51a3a2c563fe
ssdeep: 49152:I2YLzymE9tb+Z6o8HzbX37SbVhm7njsGdCM9xj4/aFGc3:lgEziZ6oo3bSZhm7jjCM9D9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15E953302854C41B3CC60B571ED1BC30F676BEB2D2F368409A24C6E7AEEBB41D866B755
sha3_384: dc40b4e93ed780cd246487401f4546310994d8c446a4529dfaa361aa63c5866735192258e437eccb2610e965267d19db
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Internet Antivirus Pro (1.0.2.9)
FileDescription: Internet Antivirus Pro Setup
FileVersion: 1.0.2.9
LegalCopyright:
Translation: 0x0409 0x04e4

Win32/Adware.InternetAntivirus also known as:

BkavW32.Common.852F2A3D
LionicTrojan.Win32.InternetAntivirus.4!c
MicroWorld-eScanGen:Adware.Heur.2H3@RuQIxT2P
FireEyeGen:Adware.Heur.2H3@RuQIxT2P
SkyhighBehavesLike.Win32.ObfuscatedPoly.tc
McAfeeFakeAlert-FTO!C1FC783F4E94
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.FraudPack.Win32.117
SangforAdware.Win32.Agent.V42o
AlibabaAdWare:Win32/FakeAV.5bccfde0
SymantecAdware.ZangoSearch
ESET-NOD32Win32/Adware.InternetAntivirus
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0CB624
AvastNSIS:FakeAV-D [Trj]
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Adware.Heur.2H3@RuQIxT2P
NANO-AntivirusTrojan.Win32.FakeAV.imuu
TencentWin32.Trojan.Fake.Ctgl
EmsisoftGen:Adware.Heur.2H3@RuQIxT2P (B)
F-SecurePrivacyRisk.SPR/Fake.In.1725870
VIPREGen:Adware.Heur.2H3@RuQIxT2P
TrendMicroTROJ_GEN.R002C0CB624
SophosGeneric Reputation PUA (PUA)
MAXmalware (ai score=99)
GoogleDetected
AviraSPR/Fake.In.1725870
VaristW32/FakeAlert.AU.gen!Eldorado
MicrosoftRogue:Win32/InternetAntivirus
ArcabitAdware.Heur.E684D1
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Adware.Heur.2H3@RuQIxT2P
CynetMalicious (score: 99)
VBA32Trojan.Ditertag
ALYacGen:Adware.Heur.2H3@RuQIxT2P
Cylanceunsafe
PandaGeneric Malware
IkarusAdWare.SuspectCRC
MaxSecureTrojan.Malware.7962891.susgen
FortinetW32/FakeAlert.MYW!tr
AVGNSIS:FakeAV-D [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan

How to remove Win32/Adware.InternetAntivirus?

Win32/Adware.InternetAntivirus removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment