PUA

ExeScript (PUA) removal instruction

Malware Removal

The ExeScript (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ExeScript (PUA) virus can do?

  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

How to determine ExeScript (PUA)?


File Info:

crc32: D44D3A20
md5: c987da1c98da4ecabb0167596a790dda
name: C987DA1C98DA4ECABB0167596A790DDA.mlw
sha1: 8196c0178c6ab0da6391c0b2e9530ed288d7e4ad
sha256: 6b90feecd001c4a396abe6a195c41db8d4c9b17bbd55b33fcf6b208690fbfb8a
sha512: 071da001c3e23809085f461f246b86322eb91b3d79f093c84a60b427e11e898b99f2a237962eaa4224033f2f925f365ffbeb60a8b66936261da08ee629f83c28
ssdeep: 768:j0ExfpdfFKwq0QeSaveaVCdMBnKimiOm9+2O8GsULdyJe2SVR:j0gfrF4laeawMgimD2OCNJeJ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

ExeScript (PUA) also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004ba1091 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop11.50247
CylanceUnsafe
SangforTrojan.Win32.Occamy.C6B
AlibabaPacked:Win32/ExeScript.224e3842
K7GWTrojan ( 004ba1091 )
Cybereasonmalicious.78c6ab
CyrenW32/CookieStealer.J.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.ExeScript.B
APEXMalicious
AvastWin32:Trojan-gen
NANO-AntivirusTrojan.Win32.Drop.hfcvkl
ViRobotBackdoor.Win32.Agent.90112.H[UPX]
SophosExeScript (PUA)
ComodoTrojWare.Win32.Downloader.Agent.LSD@83ak
McAfee-GW-EditionBehavesLike.Win32.Trojan.ph
FireEyeGeneric.mg.c987da1c98da4eca
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Generic.ASMalwS.140D1F
MicrosoftTrojan:Win32/Occamy.C6B
SUPERAntiSpywareTrojan.Agent/Gen-KillAV
GDataWin32.Trojan.PSE.1NCYJWB
AhnLab-V3Malware/Win32.Generic.C4036650
Acronissuspicious
McAfeeArtemis!C987DA1C98DA
VBA32Backdoor.Agent
IkarusTrojan.Win32.ExeScript
MaxSecureTrojan.Malware.7175203.susgen
FortinetW32/PossibleThreat
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove ExeScript (PUA)?

ExeScript (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment