Threat Database Adware Adware.Virtuvian.A

Adware.Virtuvian.A

By CagedTech in Adware

Threat Scorecard

Popularity Rank: 8,512
Threat Level: 20 % (Normal)
Infected Computers: 187
First Seen: January 11, 2013
Last Seen: June 23, 2026
OS(es) Affected: Windows

The detection of Adware.Virtuvian.A on your system indicates the presence of unwanted software that may be collecting your data, displaying intrusive advertisements, or redirecting your browsing sessions. This type of threat is commonly associated with adware programs, which are designed to generate revenue for their creators by displaying advertisements, collecting user data, or promoting affiliated products. It is essential to take immediate action to remove Adware.Virtuvian.A from your system to prevent further damage and potential security risks.

What Is Adware.Virtuvian.A?

Adware.Virtuvian.A is a type of malware that is designed to display unwanted advertisements, collect user data, or redirect browsing sessions to affiliated websites. This type of threat can be installed on your system through various means, including freeware or shareware downloads, infected email attachments, or exploited vulnerabilities in your operating system or applications. Once installed, Adware.Virtuvian.A can modify your system settings, registry entries, and browser configurations to achieve its malicious goals.

How Adware.Virtuvian.A Operates

Adware.Virtuvian.A operates by installing itself on your system and then connecting to a remote server to download advertisements, configuration files, or other malicious components. This threat can also collect user data, such as browsing history, search queries, or personal information, and transmit it to its creators or affiliated parties. Additionally, Adware.Virtuvian.A can modify your system settings, such as changing your default search engine, homepage, or browser extensions, to further compromise your system's security and performance.

Symptoms of Infection

The symptoms of Adware.Virtuvian.A infection can vary, but common indicators include unwanted advertisements, pop-ups, or redirects during browsing sessions. You may also notice changes to your system settings, such as a new default search engine or homepage, or the presence of suspicious programs or extensions in your browser. Furthermore, your system may become slower, or you may experience crashes or freezes due to the malicious activity of Adware.Virtuvian.A.

  • Unwanted advertisements or pop-ups during browsing sessions
  • Changes to system settings, such as default search engine or homepage
  • Presence of suspicious programs or extensions in your browser
  • System slowdowns, crashes, or freezes

How to Remove Adware.Virtuvian.A

  1. Boot your system in Safe Mode with Networking to prevent Adware.Virtuvian.A from loading and to allow for a more effective removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all malicious components associated with Adware.Virtuvian.A.
  3. Uninstall any suspicious programs or applications that may be related to Adware.Virtuvian.A, as they may be used to reinstall or reactivate the malware.
  4. Reset your browser settings, including Chrome, Firefox, and Edge, to their default values to remove any modifications made by Adware.Virtuvian.A.
  5. Reboot your system and perform a follow-up scan to ensure that all malicious components have been removed and that your system is clean.

Conclusion

The removal of Adware.Virtuvian.A requires a comprehensive approach that involves detecting and removing all malicious components, resetting system settings, and ensuring that your system is clean and secure. By following the steps outlined above, you can effectively remove Adware.Virtuvian.A and prevent future infections. It is essential to remain vigilant and to regularly scan your system for malware to prevent similar threats from compromising your system's security and performance.

Analysis Report

General information

Family Name: Adware.Virtuvian.A
Signature status: No Signature

Known Samples

MD5: b4e4bb965293eb2b8e31712446d2d4dd
SHA1: c0223e1aa06d021e63b873030a6a56bacb82fdd8
SHA256: 27403A741DC0F4F3E5C2754B5099DDB02D757F2D1991849A6D7FF01B84A13563
File Size: 240.13 KB, 240128 bytes
MD5: 607769603cf0e9a001a050e69742dc73
SHA1: 8b6029d744fb16f7dd8b93d3023548a9c175ee55
SHA256: 71D9C0DC358FB45F35D6B15F8C8837CF6F4EDD5F5A94FD615A24AC92F4AF02DD
File Size: 1.42 MB, 1416137 bytes
MD5: ba8dad57ebfdfd50ee6277da3f5e3a4b
SHA1: 2d172c8815e02676025ddffa168949b0e92b8d36
SHA256: 0008C402E846120D5F6279D02A3BD73B26DF0E7DC7F19DC4639857DCAF1798F2
File Size: 301.71 KB, 301711 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments zdengine.exe
Company Name
  • Bite my shiny, metal ass!
  • Dropbox, Inc.
  • zdengine
Creator py2exe 0.9.2.7
File Description
  • Dropbox 11.4.22 Installer
  • Update UEFI GOP for AMD and Nvidia cards
File Version
  • 11.4.22
  • 3.0.0.28
  • 1.9.6.5
Internal Name UEFI GOP Updater
Legal Copyright
  • Copyright © 2013
  • © Don't blink!
  • © Dropbox, Inc.
Legal Trademarks
  • Dropbox is a trademark of Dropbox, Inc.
  • Robots, Inc.
Original Filename GOPupd.exe
Product Name
  • Dropbox
  • UEFI GOP Updater
  • zdengine.exe
Product Version
  • 3.0.0.28
  • 1.9.6.5

File Traits

  • big overlay
  • dll
  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 281
Potentially Malicious Blocks: 22
Whitelisted Blocks: 259
Unknown Blocks: 0

Visual Map

x x x x x x x 0 0 x x x x x x 1 x x x 0 x 0 0 0 0 x x x x 0 1 0 1 x 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 2 3 0 0 0 0 0 0 0 0 1 0 1 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 2 2 1 0 0 1 0 0 1 0 1 1 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\2d172c8815e02676025ddffa168949b0e92b8d36_0000301711.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...