Threat Database Adware Adware.PennyBee.A

Adware.PennyBee.A

By CagedTech in Adware

Threat Scorecard

Popularity Rank: 5,138
Threat Level: 20 % (Normal)
Infected Computers: 2,734
First Seen: November 16, 2018
Last Seen: July 18, 2026
OS(es) Affected: Windows

The detection of Adware.PennyBee.A on your system indicates the presence of a potentially unwanted program that may be causing unwanted advertisements and potentially collecting user data. It is essential to understand the nature of this threat and take immediate action to remove it from your system to prevent further damage.

What Is Adware.PennyBee.A?

Adware.PennyBee.A is a type of adware program designed to display unwanted advertisements on infected systems. Adware programs like this one can be bundled with free software downloads or installed through exploits in web browsers. Once installed, they can collect user data, such as browsing history and search queries, to display targeted advertisements. While adware is not typically considered malware, it can still pose a significant threat to user privacy and system security.

How Adware.PennyBee.A Operates

Adware.PennyBee.A operates by installing itself on the system and integrating with web browsers to display advertisements. It may also collect user data, such as browsing history and search queries, to display targeted advertisements. In some cases, adware programs like this one can also install additional software or modify system settings to further compromise the system. The primary goal of adware is to generate revenue for its creators through advertisement clicks and impressions.

Symptoms of Infection

Systems infected with Adware.PennyBee.A may exhibit several symptoms, including an increase in unwanted advertisements, slow system performance, and unexpected browser behavior. Users may also notice that their search queries are being redirected to unwanted websites or that their browsing history is being collected. In some cases, adware programs like this one can also cause system crashes or freezes, especially if they are not properly configured or are conflicting with other system components.

  • Unwanted advertisements on the system or in web browsers
  • Slow system performance or freezes
  • Unexpected browser behavior, such as redirected search queries
  • Collection of user data, such as browsing history and search queries

How to Remove Adware.PennyBee.A

  1. Boot your system in Safe Mode with Networking to prevent the adware from loading and to allow for internet access to download removal tools.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all components of the adware.
  3. Uninstall any suspicious programs that may be related to the adware, taking care to review the list of installed programs carefully to avoid removing legitimate software.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any modifications made by the adware.
  5. Reboot your system and perform another full scan to ensure that all components of the adware have been removed.

Conclusion

Removing Adware.PennyBee.A from your system requires careful attention to detail and a thorough understanding of the removal process. By following the steps outlined above and using reputable anti-malware tools, you can effectively remove this unwanted program and prevent further damage to your system. It is essential to remain vigilant and to regularly scan your system for potential threats to prevent future infections. Additionally, practicing good cybersecurity habits, such as avoiding suspicious downloads and using strong antivirus software, can help to protect your system from similar threats in the future.

Analysis Report

General information

Family Name: Adware.PennyBee.A
Signature status: Self Signed

Known Samples

MD5: f5e511b31b68469101d2a76267a2b2ac
SHA1: e5ae02f4f91f8e6ed1885052bd91319527f86b6d
SHA256: 12CD518D448F46B96ABA79ADF4EE8EEA779B91BA896D1F79D598F9FF15F968D9
File Size: 223.08 KB, 223080 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Digital Signatures

Signer Root Status
Tewjalrot Fakxo Tewjalrot Fakxo Self Signed

File Traits

  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 721
Potentially Malicious Blocks: 28
Whitelisted Blocks: 692
Unknown Blocks: 1

Visual Map

0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 x x x x x x 0 0 x 0 0 0 0 0 x 0 0 x 0 0 0 x x x x 0 x 0 0 x x 0 0 0 x 0 0 0 0 0 x 0 0 0 ? x x 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 3 1 1 1 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 1 1 0 0 1 1 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 1 0 1 1 0 1 0 0 1 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\e5ae02f4f91f8e6ed1885052bd91319527f86b6d_0000223080.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...