Adware

How to remove “Win32/Adware.PCAcceleratePro_AGen.B”?

Malware Removal

The Win32/Adware.PCAcceleratePro_AGen.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.PCAcceleratePro_AGen.B virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system

How to determine Win32/Adware.PCAcceleratePro_AGen.B?


File Info:

name: CF4F6641F08F8635A764.mlw
path: /opt/CAPEv2/storage/binaries/bd7d12af4a3557822729930fedcaad77d500dfcbc5344c101fc58baf188a8576
crc32: A8C937A1
md5: cf4f6641f08f8635a764853a192839be
sha1: 1db8c2155e3cf8c2e48f81e39a33dece7ab76042
sha256: bd7d12af4a3557822729930fedcaad77d500dfcbc5344c101fc58baf188a8576
sha512: 0d94f744a0536a06660f52001b26b669ebc71f758daa3b385158d3bf5a0645b7139374950c0df2d2543280ac9cdb1e9c5536a7bcbbe97903fbc2d37278ae67ca
ssdeep: 196608:8L0nmhwS3aHyforD5C2tQuCZkdMzRA+Fdt24Wi7+B7+bOWEuIJ:lqDqSforD5C2tQuCZkdMzRAC7+B7+bOX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BA768D103DA08143E16F8AB0BD4DF27520FC5FB8FB1E959B9BE47F581D345E2292A216
sha3_384: 74978b197c747877f83c4006ae6b57285aa3931ac23c68563462f73661b8a5bebf0f46858a6e0f242e70795e18be4cbc
ep_bytes: e877100000e9000000006a1468f8367b
timestamp: 2021-07-12 01:22:53

Version Info:

CompanyName: MirxayzarAPCP Group
FileDescription: MirxayzarAPCP
InternalName: MirxayzarAPCP.exe
OriginalFilename: MirxayzarAPCP.exe
ProductName: MirxayzarAPCP
FileVersion: 1.0.6.35
LegalCopyright: Copyright MirxayzarAPCP Group 2021
ProductVersion: 1.0.6.35
Translation: 0x0409 0x04b0

Win32/Adware.PCAcceleratePro_AGen.B also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Doina.1
FireEyeGen:Variant.Application.Doina.1
McAfeeArtemis!CF4F6641F08F
MalwarebytesPUP.Optional.PCAcceleratePro
ZillyaTool.PCAccelerator.Win32.1004
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.1f08f8
ArcabitTrojan.Application.Doina.1
CyrenW32/PCAccelerate.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.PCAcceleratePro_AGen.B
KasperskyHEUR:Hoax.Win32.PCAccelerator.gen
BitDefenderGen:Variant.Application.Doina.1
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Application.Doina.1
SophosGeneric PUA BN (PUA)
EmsisoftApplication.PCFixer (A)
JiangminHoax.PCAccelerator.me
AviraADWARE/Redcap.emtqk
MAXmalware (ai score=71)
Antiy-AVLTrojan/Generic.ASMalwS.3498CE4
GDataGen:Variant.Application.Doina.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.EO.R432401
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Application.Doina.1
APEXMalicious
TencentMalware.Win32.Gencirc.11d919a4
AVGWin32:Malware-gen

How to remove Win32/Adware.PCAcceleratePro_AGen.B?

Win32/Adware.PCAcceleratePro_AGen.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment