Adware

About “Win32/Adware.PCPlus.A” infection

Malware Removal

The Win32/Adware.PCPlus.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.PCPlus.A virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Adware.PCPlus.A?


File Info:

name: D0077F26FEC7CB3FFBEE.mlw
path: /opt/CAPEv2/storage/binaries/1bb0d61540bb5a0152882499e589cf5012c8b34d49e39b0d80ec732deb790434
crc32: CE418EDE
md5: d0077f26fec7cb3ffbeed54adf364f35
sha1: 98137d14633889ef827bd5899c3873c007710073
sha256: 1bb0d61540bb5a0152882499e589cf5012c8b34d49e39b0d80ec732deb790434
sha512: 57c9187bf8b72aefa68f51111e29ece0fddbef424549ab4e7e543fc797b93ba6252cfff820ae39d43f17e0b6829801887700732eb136215b2f94f253bd6507bf
ssdeep: 24576:sL/SkfHqf6WpInIswuqCZsWcPqivHQBe6usZRsCJXl4FrDhWZY:qtHS6znIwqTNqdetsrjJXl4FR0Y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18A152319CE1E44B3DDD56A75A3C7FA3895AEBBCE4AD30739AD84930978FC7202900857
sha3_384: a6aea839be80d68e0fc151352876e9f921bd28e19ab88c447103bde90d1c5dfee5bf97f9110f565c2d2b8738b24d36c9
ep_bytes: 60be0030b9008dbe00e086ff57eb0b90
timestamp: 2010-09-27 03:02:46

Version Info:

Comments: VDoctor
CompanyName: VeniSoft Corp.
FileDescription: VDoctor 응용 프로그램
FileVersion: 2, 0, 0, 3
InternalName: VDoctor
LegalCopyright: Copyright (C) 2009 VDoctor All rights reserved.
LegalTrademarks: http://www.vdoctor.co.kr
OriginalFilename: VDoctor.exe
PrivateBuild:
ProductName: VDoctor 응용 프로그램
ProductVersion: 2, 0, 0, 3
SpecialBuild:
Translation: 0x0412 0x04b0

Win32/Adware.PCPlus.A also known as:

LionicTrojan.Win32.PCPlus.4!c
tehtrisGeneric.Malware
SkyhighArtemis
McAfeeArtemis!D0077F26FEC7
SangforAdware.Win32.Pcplus.Vxc0
AlibabaAdWare:Win32/PCPlus.7396e219
CrowdStrikewin/grayware_confidence_60% (W)
SymantecAdware.GAIN
ESET-NOD32a variant of Win32/Adware.PCPlus.A
NANO-AntivirusTrojan.Win32.Fakealert.bnnnph
AvastWin32:Adware-gen [Adw]
DrWebTrojan.Adkor.362
ZillyaTrojan.FakeAV.Win32.152015
Antiy-AVLGrayWare[AdWare]/Win32.PCPlus
XcitiumMalware@#363n5l79qds6k
GDataWin32.Application.Agent.VTK0HE
VBA32BScope.Trojan.Adkor
MalwarebytesGeneric.Malware/Suspicious
RisingPUF.KeywordPlus!8.F734 (TFE:5:VG5H9AYCoCR)
YandexTrojan.GenAsa!6AzAUdEruWU
SentinelOneStatic AI – Suspicious PE
FortinetRiskware/PCPlus
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS

How to remove Win32/Adware.PCPlus.A?

Win32/Adware.PCPlus.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment