Adware

Win32/Adware.PCAcceleratePro.I (file analysis)

Malware Removal

The Win32/Adware.PCAcceleratePro.I is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.PCAcceleratePro.I virus can do?

  • Scheduled file move on reboot detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Creates a copy of itself

How to determine Win32/Adware.PCAcceleratePro.I?


File Info:

name: F2220E6DE781FD9646F6.mlw
path: /opt/CAPEv2/storage/binaries/d33da8920f4a4f4db159d06b099e632d902515df18a2c0dc3eb63d550525f27d
crc32: 3A816F64
md5: f2220e6de781fd9646f6d18c23dfe038
sha1: b4f4fa1c5c9ecf8bd671c4f5ec3dc77627313318
sha256: d33da8920f4a4f4db159d06b099e632d902515df18a2c0dc3eb63d550525f27d
sha512: 4336861bb6d2c6d0a40b5341cdb5ad1bca11d560ca49b6cde074954f35251f27fe80a4a1595b8ec462d2841b7a65d83e382cff6d491e267f088012216a919bb5
ssdeep: 3072:NLk395hYXJpceA7dRX99ZoR+NdCotHK90jBoMbdu6ccK9G4RdDfDznQ:NQq3mJRXvMgCoN9VblccK9G4RdjQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17104020E26D0E8A7DADB4AB08AFBA73AFA35FB002561579777101F6F3620183DE15143
sha3_384: f58c750a564a03c28ddd29ed82f695582d22dbb49792f493fe72e9130ca38ba5ed9bb52aed6df8aef6034ea013ba323d
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:41

Version Info:

CompanyName: DIGI MICROSERVICE LIMITED
FileDescription: > Accelerate PC >-< Pro Installer <
FileVersion: 1.0.4.46
LegalCopyright: Copyright DIGI MICROSERVICE LIMITED 2019
ProductName: > Accelerate PC >-< Pro Installer <
ProductVersion: 1.0.4.46
Publisher: DIGI MICROSERVICE LIMITED
Translation: 0x0000 0x04e4

Win32/Adware.PCAcceleratePro.I also known as:

LionicHacktool.Win32.PCAccelerator.3!c
MicroWorld-eScanGen:Variant.Nemesis.942
FireEyeGen:Variant.Nemesis.942
McAfeeArtemis!F2220E6DE781
K7AntiVirusAdware ( 005577f11 )
AlibabaRiskWare:Win32/PCAccelerator.2acc7711
K7GWAdware ( 005577f11 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.PCAcceleratePro.I
APEXMalicious
AvastWin32:Adware-gen [Adw]
KasperskyHEUR:Hoax.Win32.PCAccelerator.gen
BitDefenderGen:Variant.Nemesis.942
TencentWin32.Trojan-psw.Pcaccelerator.Dzss
EmsisoftGen:Variant.Nemesis.942 (B)
McAfee-GW-EditionPUP-XJI-WM
SophosGeneric PUA LE (PUA)
Paloaltogeneric.ml
GDataGen:Variant.Cerbu.100290
AviraHEUR/AGEN.1122005
Antiy-AVLTrojan/Generic.ASMalwS.2C52999
ALYacGen:Variant.Cerbu.100290
MAXmalware (ai score=82)
MalwarebytesPUP.Optional.PCAcceleratePro
TrendMicro-HouseCallTROJ_GEN.R002H0CKQ21
RisingTrojan.Generic@ML.88 (RDMK:DeraX1gZ2X1Mr8lFcYvvng)
YandexTrojan.GenAsa!6dY3TStTfrU
FortinetAdware/PCAcceleratePro
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.de781f
PandaTrj/CI.A

How to remove Win32/Adware.PCAcceleratePro.I?

Win32/Adware.PCAcceleratePro.I removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment