Malware

How to remove “Downloader.Win32.PCRepair”?

Malware Removal

The Downloader.Win32.PCRepair is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.PCRepair virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

pool.ntp.org
analytics.auslogics.com
www.google-analytics.com

How to determine Downloader.Win32.PCRepair?


File Info:

crc32: 41912CA5
md5: e4016d78706ca56426edc6d0ef2f7141
name: E4016D78706CA56426EDC6D0EF2F7141.mlw
sha1: e66aba9f614becf932e07e69873cd226d424f1de
sha256: dcdf2f581b9b0a3c155fcb7e3e41ce4d415ddf77fd54a8d500cc84a05d190e24
sha512: 0ddae422d4cb5c4b74b771b75a18f4aeda5b99b98ab35f40d662e29d00fde56c78da1408d113889f498ae8157e21d84b470b83dfcc3327a27a1370df6501b0dc
ssdeep: 6144:g017vYcVQc6lbsJhcf8R3u7CTBRyh6PsLGU+EHZCUa7i2jnp:gCwcVQc6lbv+e7CT3yB9VZBa7iKnp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2008-2017 Auslogics Labs Pty Ltd
InternalName: pc-repair-kit
FileVersion: 1.8.2.9
CompanyName: TweakBit
LegalTrademarks: Copyright xa9 2008-2017 Auslogics Labs Pty Ltd
Comments: Part of TweakBit PC Repair Kit
ProductName: PCRepairKit
ProductVersion: 1.x
FileDescription: PCRepairKit Setup
OriginalFilename: pcrepairkit_stub_installer.exe
Translation: 0x0409 0x04e4

Downloader.Win32.PCRepair also known as:

FireEyeGeneric.mg.e4016d78706ca564
Qihoo-360HEUR/QVM05.1.9943.Malware.Gen
McAfeeGenericRXMS-AJ!E4016D78706C
CylanceUnsafe
ZillyaDownloader.Agent.Win32.360458
SangforMalware
K7AntiVirusTrojan ( 005329171 )
K7GWAdware ( 004f80461 )
Cybereasonmalicious.f614be
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:SilentInstaller-A [PUP]
Kasperskynot-a-virus:Downloader.Win32.PCRepair.gen
RisingPUF.Auslogics!1.AC47 (CLASSIC)
EmsisoftApplication.Downloader (A)
ComodoApplication.Win32.Auslogics.AB@80idad
F-SecurePotentialRisk.PUA/TweakBit.Gen7
DrWebProgram.Unwanted.2042
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
SophosTweak Bit FixMyPC (PUA)
JiangminDownloader.Agent.eoe
AviraPUA/TweakBit.Gen7
MAXmalware (ai score=99)
Antiy-AVLGrayWare/Win32.Auslogics.a
MicrosoftPUA:Win32/Auslogics
SUPERAntiSpywarePUP.TweakBit/Variant
ZoneAlarmnot-a-virus:Downloader.Win32.PCRepair.gen
GDataWin32.Application.Auslogics.C
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.Helper.R287739
VBA32BScope.Downloader.Agent
MalwarebytesPUP.Optional.TweakBit
ESET-NOD32a variant of Win32/Auslogics.A potentially unwanted
YandexTrojan.GenAsa!Lc7f7HISzS0
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Auslogics.A
AVGWin32:SilentInstaller-A [PUP]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Downloader.Win32.PCRepair?

Downloader.Win32.PCRepair removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment