Adware

About “Win32/Adware.Nieguide.AA” infection

Malware Removal

The Win32/Adware.Nieguide.AA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.Nieguide.AA virus can do?

  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Unconventionial language used in binary resources: Korean
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Win32/Adware.Nieguide.AA?


File Info:

name: 6F87A3ADD73E42810647.mlw
path: /opt/CAPEv2/storage/binaries/706467ce1153fd679ca422b067fc6a325d8fdbb8b40ddd8dbcc980b8cd73c419
crc32: 3001253D
md5: 6f87a3add73e42810647f9f2994cd0e2
sha1: 65ecf76a0bb59c477f0431064a4ef15e6a316359
sha256: 706467ce1153fd679ca422b067fc6a325d8fdbb8b40ddd8dbcc980b8cd73c419
sha512: ab0b2df3340d6d514655f6d98862ac4c9ff1d7c68d3611ce60f6ebf3f5ea409cfc19097eaf864e024cfdaf7dc0f873d3c5577aee67f2e0f14971e3c719263364
ssdeep: 1536:gEXqO+5J2qKFW7TVPmzAllMvUI3X1atui:fXqOqJ2RUUilMPu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1382485C07C0A4567D4E589330BAB25BABB1DAF017F07EB7F934EB55F6871444AB02628
sha3_384: a6acb579bea87945d8c4b9c444dd31973cdaf3864b708cf0c9e815b94df3e8e8b3c8b13e36ab06cea27a3a68e51d30f2
ep_bytes: 558bec6aff68b8b04000689490400064
timestamp: 2011-03-22 10:30:51

Version Info:

CompanyName:
FileDescription: hanfileupdater MFC 응용 프로그램
FileVersion: 1, 0, 0, 1
InternalName: hanfileupdater
LegalCopyright: Copyright (C) 2010
LegalTrademarks:
OriginalFilename: hanfileupdater.EXE
ProductName: hanfileupdater 응용 프로그램
ProductVersion: 1, 0, 0, 1
Translation: 0x0412 0x04b0

Win32/Adware.Nieguide.AA also known as:

LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.6f87a3add73e4281
CylanceUnsafe
K7AntiVirusAdware ( 004bb14a1 )
K7GWAdware ( 004bb14a1 )
CrowdStrikewin/malicious_confidence_70% (D)
ESET-NOD32a variant of Win32/Adware.Nieguide.AA
APEXMalicious
Paloaltogeneric.ml
NANO-AntivirusTrojan.Win32.Agent.hyvyd
AvastWin32:Adware-gen [Adw]
TencentWin32.Trojan.Dldr.Wskl
ComodoMalware@#31dv64tk6pw7v
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.PUP.dz
SophosGeneric PUA GF (PUA)
IkarusPUA.Nieguide
AviraTR/Dldr.Agent.oxx
GridinsoftRansom.Win32.Gen.sa
ViRobotAdware.Nieguide.217088.AO
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.Downloader.R13807
McAfeeArtemis!6F87A3ADD73E
TrendMicro-HouseCallTROJ_GEN.R002H0CKR21
RisingTrojan.Generic@ML.100 (RDML:Cf8JMax4+fduz3T7+NXS2Q)
YandexTrojan.GenAsa!RzCLvFxpi00
SentinelOneStatic AI – Suspicious PE
FortinetRiskware/PUP
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.a0bb59

How to remove Win32/Adware.Nieguide.AA?

Win32/Adware.Nieguide.AA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment