PUA

FileRepPup [PUP] removal

Malware Removal

The FileRepPup [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What FileRepPup [PUP] virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine FileRepPup [PUP]?


File Info:

name: A2B85FFAE4466969DF8D.mlw
path: /opt/CAPEv2/storage/binaries/8fd60cb8a8fa227c1a80581a542e439854fc4261d46bf3722b89f8e4e8c1b364
crc32: 85A2677C
md5: a2b85ffae4466969df8d4ece682c936d
sha1: a2e96bb75dbeea1853cf7bf7ac1b875c76298e48
sha256: 8fd60cb8a8fa227c1a80581a542e439854fc4261d46bf3722b89f8e4e8c1b364
sha512: e23ab7b685e489de63152f7512d6df2c0fa996647173e9c9c2930f7a3bde3cc8285ede0863939e0319990583f0a7e6c627e772c50415cddac2100f8b94f7c8d1
ssdeep: 98304:nxI8+eVQlG4ifmtsn5SbWf+YFCr9v13IVCs:GeVesnQaf+HDO7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16306E023F652C4B2C119257015B77B39AE78CB611E258B83D7E4DEB87D32760A71B20E
sha3_384: c5e5784964d860afd8ecb4d08500ceb211fc4bc1de844505b74bbf5d75863c663da004ca32bc5a59d56e52a1cb812460
ep_bytes: 558bec6aff68803a730068e8034f0064
timestamp: 2022-02-23 09:10:31

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

FileRepPup [PUP] also known as:

LionicTrojan.Win32.Generic.liRL
tehtrisGeneric.Malware
FireEyeGeneric.mg.a2b85ffae4466969
CAT-QuickHealHacktool.Flystudio.16559
McAfeeGenericRXAE-NF!A2B85FFAE446
CylanceUnsafe
Sangfor[ARMADILLO V1.XX – V2.XX]
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.75dbee
BitDefenderThetaGen:NN.ZexaF.34606.Kt0@aC4ttYfb
CyrenW32/Trojan.GRW.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/FlyStudio.HackTool.A potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0PC522
Paloaltogeneric.ml
CynetMalicious (score: 100)
AlibabaTrojan:Win32/FlyStudio.c31f0c22
AvastFileRepPup [PUP]
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
ZillyaTrojan.Blamon.Win32.3136
TrendMicroTROJ_GEN.R002C0PC522
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SophosGeneric PUA KC (PUA)
IkarusPUA.BlackMoon
JiangminRiskTool.IMEStartup.evt
AviraTR/Blamon.hwuxe
Antiy-AVLTrojan/Generic.ASCommon.FA
ZoneAlarmHEUR:Trojan.Win32.Blamon.gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Malware/Win32.Generic.C3242232
VBA32BScope.Trojan.Agent
MalwarebytesPUP.Optional.ChinAd
APEXMalicious
RisingTrojan.Injector!1.A1C3 (CLOUD)
YandexTrojan.Blamon!bC6vVSGD9GI
SentinelOneStatic AI – Malicious PE
FortinetW32/CoinMiner.ELG!tr.pws
AVGFileRepPup [PUP]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove FileRepPup [PUP]?

FileRepPup [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment