PUA

About “PUA.AgentFC.S21583860” infection

Malware Removal

The PUA.AgentFC.S21583860 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.AgentFC.S21583860 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Checks the CPU name from registry, possibly for anti-virtualization

How to determine PUA.AgentFC.S21583860?


File Info:

crc32: B8BDF24C
md5: 4635717286a110be1088df0100dec93f
name: 4635717286A110BE1088DF0100DEC93F.mlw
sha1: 33a22611a88d5d8e552a444300d1fe8f65373411
sha256: 20592a6dec6017911a167580ae4c8624f8bc5675081c9e740030941340c86bd6
sha512: 585a91c78ea6646c393313f5b19a4e69d8467cb92eec73d264c94bf32f83fa0e4b9d8efeea4f5936ec608d138c2d80d773a4cb13f0afb30957335b5f59c358f9
ssdeep: 6144:Be5QxJwmVOp+gd6CVteoSPK7T0jZcCOX55A1VZD5mS0lveZ0q2wMfjDW8yXGD:BKQfHsdHDNwi/X5QhAv20qLMfjDyk
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright Blizzard xa9 2016
Assembly Version: 5.1.1.9
InternalName: launcher.exe
FileVersion: 5.1.1.9
CompanyName: Activision Blizzard
LegalTrademarks:
Comments:
ProductName: launcher
ProductVersion: 5.1.1.9
FileDescription: Battle NET lancher
OriginalFilename: launcher.exe

PUA.AgentFC.S21583860 also known as:

K7AntiVirusRiskware ( 0050b1e11 )
LionicTrojan.MSIL.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
CAT-QuickHealPUA.AgentFC.S21583860
ALYacAdware.GenericKD.36896891
CylanceUnsafe
ZillyaTool.GameHack.Win32.15307
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:MSIL/MalwareX.a4f07326
K7GWRiskware ( 0050b1e11 )
Cybereasonmalicious.1a88d5
CyrenW32/S-0e9168d3!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Riskware.GameHack.Z
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan.MSIL.Generic
BitDefenderAdware.GenericKD.36896891
NANO-AntivirusTrojan.Win32.Mlw.eyyvah
MicroWorld-eScanAdware.GenericKD.36896891
TencentMalware.Win32.Gencirc.114cef2f
Ad-AwareAdware.GenericKD.36896891
SophosGeneric ML PUA (PUA)
ComodoApplication.MSIL.GameHack.Z@7kilc4
BitDefenderThetaGen:NN.ZemsilF.34294.Cm1@aeZjM4d
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
FireEyeGeneric.mg.4635717286a110be
EmsisoftAdware.GenericKD.36896891 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.zfcx
AviraHEUR/AGEN.1128553
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.25061B5
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataAdware.GenericKD.36896891
AhnLab-V3Unwanted/Win32.GameHack.R219092
Acronissuspicious
McAfeeGenericRXCU-UA!4635717286A1
MAXmalware (ai score=99)
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.3635851226
PandaTrj/GdSda.A
YandexTrojan.Agent!Wp87IJko2jg
IkarusPUA.MSIL.Riskware
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.SHR!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove PUA.AgentFC.S21583860?

PUA.AgentFC.S21583860 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment