Categories: Adware

Win32/Adware.UCmore (file analysis)

The Win32/Adware.UCmore is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.UCmore virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

www.bing.com
users.ucmore.com
users2.ucmore.com
www.ucmore.com
fonts.googleapis.com
ucmore.com

How to determine Win32/Adware.UCmore?


File Info:

crc32: 05DE5E8Fmd5: 12ae14100cb7347075b9ecf03dd4b3e2name: mmabrowsersetup.exesha1: e92315aeb037e5c894cf1d9ec542423c65fb1f7dsha256: 587341986cabd488d1c34a0915ce9aa3dab656a17cded5ad7ed4e07d556c88a1sha512: 94b6f37bdd1df7d28517b60b184a999c2ac7dece91f71b728968e057c5d808b41199eeda5f9a1497a7c3c2831c2db7ae60baf3c0437a2eba757b0927523f3b8essdeep: 24576:MVH268fEDmaWku6RsrvqAirYRsaqqFjoRzgPs3KJ9rTjDKAj+FJ+IM0TI/nQP51:MVW68fEya/RNVYRSq6aPw8jsKQCnA1type: PE32 executable (GUI) Intel 80386, for MS Windows, InnoSetup self-extracting archive

Version Info:

0: [No Data]

Win32/Adware.UCmore also known as:

MicroWorld-eScan Gen:Adware.Heur.bu8@R0wvXIfi
FireEye Gen:Adware.Heur.bu8@R0wvXIfi
VIPRE Trojan.Win32.Generic!BT
K7AntiVirus Riskware ( 0040f0f51 )
BitDefender Gen:Adware.Heur.bu8@R0wvXIfi
K7GW Riskware ( 0040f0f51 )
Cybereason malicious.00cb73
F-Prot W32/UCMore.A@adw
Paloalto generic.ml
ClamAV Win.Adware.UCMore-4
Kaspersky not-a-virus:AdWare.Win32.Ucmore
Alibaba AdWare:Win32/Ucmore.a19bbbc2
NANO-Antivirus Riskware.Win32.Ucmore.baoir
ViRobot Adware.Ucmore.1778910
Emsisoft Gen:Adware.Heur.bu8@R0wvXIfi (B)
Comodo Malware@#2oayyr2d7qkkj
F-Secure Adware.ADSPY/Bar.Ucmore
DrWeb Adware.Ucmore
CMC Trojan-Mailfinder.Win32.Agent!O
Sophos UCMore (PUA)
Cyren W32/UCMore.NOID-8117
Avira ADSPY/Bar.Ucmore
Arcabit Adware.Heur.EAA504
ZoneAlarm not-a-virus:AdWare.Win32.Ucmore
Microsoft PUA:Win32/Bitrepeyp.C
VBA32 AdWare.Ucmore
ESET-NOD32 Win32/Adware.UCmore
eGambit Generic.Adware
GData Gen:Adware.Heur.bu8@RW5oZRbi
Panda Generic Malware

How to remove Win32/Adware.UCmore?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Win32:VB-NPD [Wrm] removal instruction

The Win32:VB-NPD [Wrm] is considered dangerous by lots of security experts. When this infection is…

36 seconds ago

About “Symmi.4579” infection

The Symmi.4579 is considered dangerous by lots of security experts. When this infection is active,…

2 mins ago

What is “Lazy.487114”?

The Lazy.487114 is considered dangerous by lots of security experts. When this infection is active,…

7 mins ago

Malware.AI.91208316 (file analysis)

The Malware.AI.91208316 is considered dangerous by lots of security experts. When this infection is active,…

18 mins ago

Malware.AI.2014257291 removal guide

The Malware.AI.2014257291 is considered dangerous by lots of security experts. When this infection is active,…

24 mins ago

About “Trojan.Downloader.Small.ABNE” infection

The Trojan.Downloader.Small.ABNE is considered dangerous by lots of security experts. When this infection is active,…

27 mins ago