PUA

Http File Server (PUA) removal guide

Malware Removal

The Http File Server (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Http File Server (PUA) virus can do?

  • Creates RWX memory
  • Starts servers listening on 0.0.0.0:80
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Http File Server (PUA)?


File Info:

crc32: 7AB0C126
md5: 3952388f35347cf5800baf948d18daba
name: 3952388F35347CF5800BAF948D18DABA.mlw
sha1: d4c19611e510e3a6fd38ab77af3fc5ab5dd06035
sha256: 47579c23df3668b60d9eb27a1bce13114114142f1f3458de3f304791a1f52f90
sha512: e5a0186661c7b2f57be5d1493cbbddcc5d8b13b44f80b687295c2d8802a6e7fb5aa82375de952be2d05fe3dc9898ee4a8fd9caf86e11bd773796033c2caabd9a
ssdeep: 12288:amaWf7KGMdlYhryQ1VaMFxPdXoPUXBTrIePbCAKZYJHjCKxdL9H06PhQZ5RvWnk:LMdSyQ1VJd3BHR2Z2nd1WZL3HQzc
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2002 Massimo Melina (www.rejetto.com)
InternalName: HFS
FileVersion: 2.4.0.0
CompanyName: rejetto
LegalTrademarks:
Comments:
ProductName: Http File Server x968fx6ce2x6c49x5316x7248
ProductVersion: 2.4
FileDescription:
OriginalFilename: hfs.exe
Translation: 0x0804 0x03a8

Http File Server (PUA) also known as:

K7AntiVirusUnwanted-Program ( 004d38111 )
ALYacTrojan.GenericKD.41714181
CylanceUnsafe
ZillyaTrojan.ServerWeb.Win32.28
SangforMalware
K7GWUnwanted-Program ( 004d38111 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Server-Web.HFS.A potentially unsafe
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.GenericKD.41714181
BitDefenderTrojan.GenericKD.41714181
ViRobotAdware.Agent.788480.M
MicroWorld-eScanTrojan.GenericKD.41714181
Ad-AwareTrojan.GenericKD.41714181
SophosHttp File Server (PUA)
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
Trapminesuspicious.low.ml.score
FireEyeTrojan.GenericKD.41714181
EmsisoftTrojan.GenericKD.41714181 (B)
WebrootW32.Adware.Gen
Antiy-AVLGrayWare/Win32.Presenoker
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Generic.D27C8205
AegisLabTrojan.Win32.Generic.4!c
AhnLab-V3PUP/Win32.HFS.R99646
McAfeeArtemis!3952388F3534
PandaTrj/CI.A
IkarusPUA.Server-Web.Hfs
FortinetRiskware/Server_Web_HFS
AVGWin32:Malware-gen

How to remove Http File Server (PUA)?

Http File Server (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment