PUA

PUA.AgentPMF.S18931605 removal

Malware Removal

The PUA.AgentPMF.S18931605 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.AgentPMF.S18931605 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine PUA.AgentPMF.S18931605?


File Info:

name: 593B8344442411C36D11.mlw
path: /opt/CAPEv2/storage/binaries/2af29789df1f2fb329797985fd09844d999a03c888e01732c065dfe1a13f286f
crc32: ABC3617D
md5: 593b8344442411c36d11ffc0e2d39da9
sha1: 37eb5e0e436559e62f14eab84fd9f6ae2985128e
sha256: 2af29789df1f2fb329797985fd09844d999a03c888e01732c065dfe1a13f286f
sha512: a35525bd4b88282acb62b6b868946c6f1d868a6a1eb611d839a5ed63f1caf771bf181fcb8bc283cfc53bbce4f87e9eeb085d39a366047413e37377eca14156b5
ssdeep: 49152:FAj7f0eCok3tcj6zMtLY4hbvCjgQKcI5ECuNPjt/9QVcsy39yToLeHZ6O:G30NtcGzGYK+jdKc4mN5/9YJpV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CBD53303F3D349BAE619157DC496C8506E27FCB86DF260052DB8EE0D1A7DAC29C39B25
sha3_384: df9809452f288429a6b5d5542d645a555387178c3998b73b793f57d6616952cdc67cfefd94a4fb0de01dfcc62af61f3e
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2012-10-09 08:48:22

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Tempora Setup
FileVersion:
LegalCopyright:
ProductName: Tempora
ProductVersion: 1.3.3.7
Translation: 0x0000 0x04b0

PUA.AgentPMF.S18931605 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanApplication.DealAlpha.2.Gen
FireEyeApplication.DealAlpha.2.Gen
CAT-QuickHealPUA.AgentPMF.S18931605
ALYacApplication.DealAlpha.2.Gen
CylanceUnsafe
SangforTrojan.Win32.Wacatac.B
K7AntiVirusTrojan ( 0056e5201 )
AlibabaTrojan:Win32/Tnega.7212b200
K7GWTrojan ( 0056e5201 )
Cybereasonmalicious.444241
ArcabitApplication.DealAlpha.2.Gen
CyrenW32/Agent.CPP.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
Paloaltogeneric.ml
ClamAVWin.Adware.Dealalpha-9835537-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderApplication.DealAlpha.2.Gen
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:AdwareX-gen [Adw]
EmsisoftApplication.DealAlpha.2.Gen (B)
DrWebTrojan.DownLoader36.48458
McAfee-GW-EditionBehavesLike.Win32.PUP.vc
SophosGeneric ML PUA (PUA)
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1206258
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.317E1E9
MicrosoftProgram:Win32/Wacapew.C!ml
GDataGen:Variant.Zusy.369130
McAfeeArtemis!593B83444424
VBA32Adware.Vosteran
MalwarebytesAdware.DownloadAssistant
RisingTrojan.Kryptik!1.AA23 (CLOUD)
MaxSecureTrojan.Malware.12142042.susgen
FortinetW32/Kryptik.GZFR!tr
BitDefenderThetaGen:NN.ZexaCO.34114.wA0@aSeYp8dc
AVGWin32:AdwareX-gen [Adw]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove PUA.AgentPMF.S18931605?

PUA.AgentPMF.S18931605 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment