Adware

Win64/Adware.SecureDuck.A information

Malware Removal

The Win64/Adware.SecureDuck.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/Adware.SecureDuck.A virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Repeatedly searches for a not-found browser, may want to run with startbrowser=1 option
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Steals private information from local Internet browsers
  • Attempts to identify installed analysis tools by a known file location
  • Anomalous binary characteristics

How to determine Win64/Adware.SecureDuck.A?


File Info:

name: F6988EED5CC6392F99D3.mlw
path: /opt/CAPEv2/storage/binaries/a96bbb7a79487779c29f5d645d6d72604c115a4ce53f44dfd29e62220c118b14
crc32: 5BF10978
md5: f6988eed5cc6392f99d3dcc7535f3529
sha1: 6919027b13c3793074e41ab7c67f27b79b746311
sha256: a96bbb7a79487779c29f5d645d6d72604c115a4ce53f44dfd29e62220c118b14
sha512: 2352a1d3de8efe4bcd6c5d0d506bd93dc42a99f9e0480d5cd99fd28eb6c6ea1046faa274cfca1e46160ec14a5e65951dd96ea44ef1745d4dc33bd9033b13fca4
ssdeep: 24576:aKQxhdiAfVW78bJgm37mCvAzfdsQ/PBpynfoFgckEZ:nQtdC+QHyfckEZ
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1F6061606769CE9A8D0769238A7735BC1E379B80503B0CADF0793076EDF5A2927E39750
sha3_384: 4b0a9c92c24ac07faeb686d00b12bf966c9929be18a046dfb6e213167a178737ae679b6df05f173e6524240c846ee96a
ep_bytes: 4883ec28e81b0800004883c428e97afe
timestamp: 2021-04-23 09:37:09

Version Info:

0: [No Data]

Win64/Adware.SecureDuck.A also known as:

LionicTrojan.Win32.Ulise.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38246566
FireEyeTrojan.GenericKD.38246566
CAT-QuickHealTrojan.MikeyRI.S20994645
CylanceUnsafe
ZillyaAdware.SecureDuck.Win64.1
SangforTrojan.Win32.Wacatac.B
K7AntiVirusAdware ( 0057f5391 )
K7GWAdware ( 0057f5391 )
CyrenW64/Johnnie.V.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Adware.SecureDuck.A
BitDefenderTrojan.GenericKD.38246566
AvastFileRepMalware
Ad-AwareTrojan.GenericKD.38246566
EmsisoftTrojan.GenericKD.38246566 (B)
F-SecureAdware.ADWARE/Redcap.yxyfx
VIPREWin64.Adware.SecureDuck
McAfee-GW-EditionArtemis!Trojan
SophosGeneric PUA GJ (PUA)
GDataTrojan.GenericKD.38246566
JiangminTrojan.Generic.gzwgn
AviraADWARE/Redcap.yxyfx
ArcabitTrojan.Generic.D24798A6
ViRobotAdware.Secureduck.3880328
MicrosoftProgram:Win32/Wacapew.C!ml
CynetMalicious (score: 99)
AhnLab-V3Malware/Win.Generic.R424710
McAfeeGenericRXAA-AA!F6988EED5CC6
MAXmalware (ai score=80)
MalwarebytesMalware.AI.1557315157
TrendMicro-HouseCallTROJ_GEN.R03BH09F321
eGambitPE.Heur.InvalidSig
FortinetW64/Johnnie.88B6!tr
AVGFileRepMalware
MaxSecureTrojan.Malware.118250347.susgen

How to remove Win64/Adware.SecureDuck.A?

Win64/Adware.SecureDuck.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment