PUA

Cydoor (PUA) removal instruction

Malware Removal

The Cydoor (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cydoor (PUA) virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Cydoor (PUA)?


File Info:

crc32: 675B4F8A
md5: bcbe838cb78f8bbcbd58e44d47887a67
name: babylon31.exe
sha1: a9763cb9d6a012fa9d7aa389a24863faf6969840
sha256: 0e045b595617e067b2fa96e1255142e0aeb6acde5986521ffe0431bfe40a3e59
sha512: c9083006f76aa3aa8974e92e1940cab6da73bb5cece47fc341e27b1594a9431c1235d80bfbf3cf5b04cbc1b25f3e612d48fb2cf90171488d8aa6bddfad4557f1
ssdeep: 24576:AuVpxvYmSldSiYgS2uWsnQPYt+gJMG3t3Moz5hZi2mBGGF7Qyc1zya/z08+Hu:DVvSnruL+gJMitc8mBGwct1zX/zZ
type: PE32 executable (GUI) Intel 80386, for MS Windows, ZIP self-extracting archive (WinZip)

Version Info:

0: [No Data]

Cydoor (PUA) also known as:

McAfeeArtemis!BCBE838CB78F
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderGen:Adware.Heur.uK0@Rui204ni
Cybereasonmalicious.cb78f8
TrendMicroADW_CYDOOR.A
ClamAVWin.Adware.Cydoor-28
GDataGen:Adware.Heur.uK0@Rui204ni
NANO-AntivirusTrojan.Win32.Cydoor.buyhei
TencentWin32.Adware.Cydoor.Pjdu
SophosCydoor (PUA)
F-SecureAdware.ADWARE/Cydoor.owcbg
McAfee-GW-EditionAdware-CyDoor
FireEyeGen:Adware.Heur.uK0@Rui204ni
EmsisoftGen:Adware.Heur.uK0@Rui204ni (B)
JiangminTrojan.Generic.dlxct
WebrootW32.Suspicious.Heur
AviraADWARE/Cydoor.L.1
Endgamemalicious (moderate confidence)
ArcabitAdware.Heur.ECE694
MicrosoftTrojan:Win32/Bitrep.B
TACHYONTrojan-Clicker/W32.Cydoor.1552013
MAXmalware (ai score=99)
PandaTrj/CI.A
TrendMicro-HouseCallADW_CYDOOR.A
RisingTrojan.Bitrep!8.F596 (CLOUD)
YandexAdware.Cydoor!3Mn5twJPEDo
FortinetAdware/CyDoor
AVGWin32:Spyware-gen [Spy]
AvastWin32:Spyware-gen [Spy]

How to remove Cydoor (PUA)?

Cydoor (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment