PUA

PUA.AgentPMF.S18860923 information

Malware Removal

The PUA.AgentPMF.S18860923 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.AgentPMF.S18860923 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs
  • Attempts to identify installed AV products by installation directory

How to determine PUA.AgentPMF.S18860923?


File Info:

crc32: 91B00381
md5: c41eb20f82cdb4ee04d2e51275c14fc7
name: C41EB20F82CDB4EE04D2E51275C14FC7.mlw
sha1: 05926ab1f6d8770774921d3936df72ab569a320d
sha256: d44bd88a27ac7909f69cfeee88f70523d3831715858bdfac009fcc448eb7fa17
sha512: 4fc31340e16f6f9ed0927cc8379ba6334630d11e4bd343e9a146ddf9617d73b16b97889d0093a8b4851d6fc6ac0669194f17279c6e6d7b848fb666017388f45e
ssdeep: 49152:CROAczUYbUfIeIFGcpHD2l4pw+X7tFqF3nbtsO89yToL+ctMfm91EIJc:bAcoYYf/QTpHD2CtkF3hVOB1EIJc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName:
Comments: This installation was built with Inno Setup.
ProductName: Voluptatem
ProductVersion: 4.4.9.5
FileDescription: Voluptatem Setup
Translation: 0x0000 0x04b0

PUA.AgentPMF.S18860923 also known as:

K7AntiVirusTrojan ( 0056e5201 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader36.42781
CynetMalicious (score: 99)
CAT-QuickHealPUA.AgentPMF.S18860923
ALYacApplication.DealAlpha.2.Gen
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaAdWare:Win32/Vosteran.605ba21c
K7GWTrojan ( 0056e5201 )
Cybereasonmalicious.f82cdb
CyrenW32/Agent.CNI.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
ClamAVWin.Adware.Dealalpha-9835083-0
BitDefenderTrojan.GenericKD.45838367
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanTrojan.GenericKD.45838367
TencentWin32.Adware.Vosteran.Svhe
SophosMal/Generic-R
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.InstallCore.vc
FireEyeTrojan.GenericKD.45838367
EmsisoftTrojan.GenericKD.45838367 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Adware.Gen
AviraTR/Crypt.Agent.inxps
Antiy-AVLTrojan/Generic.ASMalwS.317EF8E
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataApplication.DealAlpha.2.Gen
McAfeeArtemis!C41EB20F82CD
MAXmalware (ai score=85)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesAdware.DownloadAssistant
PandaTrj/CI.A
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
FortinetW32/Kryptik.GZFR!tr
AVGWin32:AdwareX-gen [Adw]
Paloaltogeneric.ml

How to remove PUA.AgentPMF.S18860923?

PUA.AgentPMF.S18860923 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment