Adware

How to remove “Win32/Adware.RegistryEasy”?

Malware Removal

The Win32/Adware.RegistryEasy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.RegistryEasy virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Adware.RegistryEasy?


File Info:

name: 8DEE08FA98D769F80BF9.mlw
path: /opt/CAPEv2/storage/binaries/9dc0e2ee6bb81fe79b8a42bda0eb9ad6108d1ace9569241213081c7d292c78ad
crc32: 4C864F16
md5: 8dee08fa98d769f80bf977d7169bed73
sha1: 133b035432bab68e5b7e304c205441e28a8739fd
sha256: 9dc0e2ee6bb81fe79b8a42bda0eb9ad6108d1ace9569241213081c7d292c78ad
sha512: adcadb708b65d939d7ff008d9e2979ed1ea061d7b66d3252ec7fa6328fcf682cbbb5279d8331934c15e97a36a0daf0e6f0ead647f7bc649b567eefb52f9185a4
ssdeep: 24576:jve3nKzWaR552ctz/GFYeQT9t3wMKiA3xr74dye3G9EnsfKfcoenanYHSaW0ACcl:re5hAKxwQMeKRIJgALZem+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13C957D12B182C873C1635B388C2BD394A529BB541E2455873FFB9F4C5FBA293B92D193
sha3_384: 4bf61d06e5db351ca14056a99a1802f72940fa6202f305d2dfded392cd6b525c360c347222d52ab957af865efdae3ab5
ep_bytes: 558becb9040000006a006a004975f951
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Adware.RegistryEasy also known as:

LionicTrojan.Win32.RegistryEasy.4!c
MicroWorld-eScanTrojan.GenericKD.38168849
FireEyeTrojan.GenericKD.38168849
McAfeeArtemis!8DEE08FA98D7
CylanceUnsafe
ZillyaAdware.RegistryEasy.Win32.51
AlibabaAdWare:Win32/Generic.221684e6
SymantecRegistryGreat
ESET-NOD32a variant of Win32/Adware.RegistryEasy
APEXMalicious
BitDefenderTrojan.GenericKD.38168849
Ad-AwareTrojan.GenericKD.38168849
SophosGeneric PUA BD (PUA)
TrendMicroTROJ_GEN.R002C0OL621
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
EmsisoftTrojan.GenericKD.38168849 (B)
GDataWin32.Application.RegistryEasy.A
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
MAXmalware (ai score=89)
TrendMicro-HouseCallTROJ_GEN.R002C0OL621
YandexPUA.RegistryEasy!Plw/0bbhNMY
FortinetRiskware/RegistryEasy
Cybereasonmalicious.432bab
PandaTrj/CI.A

How to remove Win32/Adware.RegistryEasy?

Win32/Adware.RegistryEasy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment