PUA

ForceLibrary (PUA) (file analysis)

Malware Removal

The ForceLibrary (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ForceLibrary (PUA) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs

How to determine ForceLibrary (PUA)?


File Info:

crc32: 788D73B8
md5: 551ab65daa00a24089b40725d9f97be1
name: uniextract161.exe
sha1: 2e31438e3da025877b3394344d54d7c31c646863
sha256: 6df6a742c23eefa480cb37bad3835c5005801c61168d32610504eeb72c7b7f30
sha512: 179cb4ac7579ceeb35e8876ce57e3776722a39d37d0cfd02cfe492776aa08cdfe687f8601074c4c21895f516ff66c126938498fe6b8720a148a8d31db50cfcb6
ssdeep: 98304:8T5CA7FsoyEuYFV2rNDw7TyIZu16Mxb9bgyP3HVj4jBttyJOA+N:89CAJBuM2rN07uIMxZbBPXVROAa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: GNU General Public License v2
FileVersion: 1.6.1
CompanyName: Jared Breland
Comments: This installation was built with Inno Setup.
ProductName: Universal Extractor
ProductVersion: 1.6.1
FileDescription: Package for Universal Extractor
Translation: 0x0000 0x04b0

ForceLibrary (PUA) also known as:

SophosForceLibrary (PUA)
RisingTrojan.Kryptik!8.8 (CLOUD)
eGambitUnsafe.AI_Score_100%

How to remove ForceLibrary (PUA)?

ForceLibrary (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment