PUA

GMER (PUA) removal guide

Malware Removal

The GMER (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What GMER (PUA) virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine GMER (PUA)?


File Info:

name: C1F1EA703121FBF0AA07.mlw
path: /opt/CAPEv2/storage/binaries/08fdfed7ba8221333926084b5210fef3a4552a5c0da21b8b43a7bb785c5d9e4a
crc32: CD05CD01
md5: c1f1ea703121fbf0aa075364682efb18
sha1: 0add78f5ed89a42b4a5bf42b2eb5fb3729548ee1
sha256: 08fdfed7ba8221333926084b5210fef3a4552a5c0da21b8b43a7bb785c5d9e4a
sha512: c4138dc5e1f1283235737996c2d7205ab5fd0612437631f662cccaa0ee9b16293b637600508968e6c8ce0ea0ac2c24c071ee2676524d8efef2792f64579f8fda
ssdeep: 98304:1MRfipqMsxK8FZu/eiXHhCGVk/feFJmaY350R+BCbVBMcqCG/kgvQfrYPhs0H6:1M8p+xVK/eaVk/GnTY350lVBpGceorSa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1164633DE0291D645D6E3CE7B9540805E143857EB4A1371BFEE76F042DA48BF2A2F92C0
sha3_384: 00c09990a6f36cf6c0be4a593405b00de53108a1e66b357b1bd3d4dcd813af95d0fa54d755c6577961c76f6f6107b73f
ep_bytes: 68db4140db1002da9610d0368580b62d
timestamp: 2014-05-11 20:03:36

Version Info:

0: [No Data]

GMER (PUA) also known as:

BkavW32.AIDetectMalware
SkyhighBehavesLike.Win32.Generic.tc
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan ( 004bcce41 )
K7AntiVirusTrojan ( 004bcce41 )
CynetMalicious (score: 100)
F-SecureHeuristic.HEUR/AGEN.1331407
SophosGMER (PUA)
AviraHEUR/AGEN.1331407
Antiy-AVLTrojan[Downloader]/Win32.AdLoad.gen
XcitiumPacked.Win32.MUPX.Gen@24tbus
MaxSecureTrojan.Malware.121218.susgen

How to remove GMER (PUA)?

GMER (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment