Adware

Win32/Adware.Neoreklami.LQ (file analysis)

Malware Removal

The Win32/Adware.Neoreklami.LQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.Neoreklami.LQ virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Detects VirtualBox using WNetGetProviderName trick
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Appears to use command line obfuscation
  • A script or command line contains a long continuous string indicative of obfuscation
  • Attempts to execute suspicious powershell command arguments
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Adware.Neoreklami.LQ?


File Info:

name: B02DA373FC0DBC669463.mlw
path: /opt/CAPEv2/storage/binaries/3b4014eb52a441b538db83494a62d0cc8a6a1b27335d7efce9fc692aff9b3605
crc32: 2A53A780
md5: b02da373fc0dbc66946308fc5ec8e74a
sha1: 0b7f39128e6935dd677e11601f2dc0796ab9f782
sha256: 3b4014eb52a441b538db83494a62d0cc8a6a1b27335d7efce9fc692aff9b3605
sha512: e6d8a1a591bbf7c683854910931584e3e7aadab95567873917bcc2284982ba5798f40099a1d179752684fa4f202b330ba916bb3192140ef348dc249c17640bbb
ssdeep: 196608:91OmL4b8yi3Fv0E07b+pRWywDAa49sEN97W6C+GJABmh4EpQ2p9C:3OUO43Fv0/7b+rWBDAXnL4Jxh4ErC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10166333136E099B6DA64E8760E548FCB71E0C26C0E70963343C9474DAE39B9AE177736
sha3_384: 7dadc6c58acfad021e27bf82b74b004d7b542afc494b36743041a54e323d627bada8579071e4aa631c8a57530cdd85b5
ep_bytes: 558bec6aff68e0b94100682c4a410064
timestamp: 2010-11-18 16:27:35

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z Setup SFX
FileVersion: 9.20
InternalName: 7zS.sfx
LegalCopyright: Copyright (c) 1999-2010 Igor Pavlov
OriginalFilename: 7zS.sfx.exe
ProductName: 7-Zip
ProductVersion: 9.20
Translation: 0x0409 0x04b0

Win32/Adware.Neoreklami.LQ also known as:

LionicRiskware.Win32.Jaik.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jaik.48175
FireEyeGen:Variant.Jaik.48175
McAfeeArtemis!B02DA373FC0D
CylanceUnsafe
SangforTrojan.Win32.Sabsik.TE
AlibabaAdWare:Win32/Neoreklami.888dcc0f
BitDefenderThetaGen:NN.ZexaF.34182.@NW@aagefqd
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Neoreklami.LQ
TrendMicro-HouseCallTROJ_GEN.R002H09B322
Paloaltogeneric.ml
KasperskyTrojan-Dropper.Win32.Agent.tetzxu
BitDefenderGen:Variant.Jaik.48175
AvastWin32:Adware-gen [Adw]
SophosGeneric PUA AL (PUA)
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
EmsisoftGen:Variant.Jaik.48175 (B)
IkarusPUA.Neoreklami
AviraHEUR/AGEN.1106374
Antiy-AVLTrojan/Generic.ASMalwS.351DB1C
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
GDataGen:Variant.Jaik.48175
CynetMalicious (score: 100)
ALYacGen:Variant.Jaik.48175
MAXmalware (ai score=81)
MalwarebytesAdware.Neoreklami
APEXMalicious
RisingAdware.Neoreklami!1.ABC4 (CLOUD)
YandexPUA.Neoreklami!LIzYY5DBCSc
SentinelOneStatic AI – Suspicious SFX
FortinetAdware/Neoreklami
AVGWin32:Adware-gen [Adw]

How to remove Win32/Adware.Neoreklami.LQ?

Win32/Adware.Neoreklami.LQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment