PUA

About “PUA.AgentPMF.S21238239” infection

Malware Removal

The PUA.AgentPMF.S21238239 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.AgentPMF.S21238239 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine PUA.AgentPMF.S21238239?


File Info:

name: 627064CF34F9CCF41E1F.mlw
path: /opt/CAPEv2/storage/binaries/ce3e5680a9120f34e86d19244326a9a7b4087fe2dcde6addf8fe9a24822adda3
crc32: FE3125D4
md5: 627064cf34f9ccf41e1fb11a7586cbd9
sha1: da34c96ca7b3bddbfb5c1182249311d088ad4f24
sha256: ce3e5680a9120f34e86d19244326a9a7b4087fe2dcde6addf8fe9a24822adda3
sha512: b669877637484fc8899700a45b4d338573975b651d8f96dfcd63af4d6b49ac499b70d9937e5511ed378c9c55ebae433607b31a561e969386a74940a84bbe4f99
ssdeep: 12288:GBKwBlaBNWxB+xchB32B29D/BwGGBcDvgSfqppmvufOgY7a+s0:C5lGY+xcPC29DZw5y5aIvufnXI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13A25097D8BEF5930FB78A07068B4FE6DF56E99300B6E96812514E740AD32F4D8B051CA
sha3_384: 2b6291d6c3dacc2d2245650d25c37aa17dc85babb15f9af504cfe4d40f0ef103689697f33b94e256f287100e1ebad8f4
ep_bytes: 558bec6aff6848ca4600687ea5460064
timestamp: 2021-06-09 05:59:45

Version Info:

0: [No Data]

PUA.AgentPMF.S21238239 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.627064cf34f9ccf4
CAT-QuickHealPUA.AgentPMF.S21238239
McAfeeGenericRXAA-AA!627064CF34F9
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058214e1 )
K7GWTrojan ( 0058214e1 )
BitDefenderThetaGen:NN.ZexaE.34062.8yW@aanwVpci
CyrenW32/Ekstak.BG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLIN
APEXMalicious
KasperskyHEUR:Trojan.Win32.Ekstak.gen
BitDefenderGen:Variant.Zusy.386742
MicroWorld-eScanGen:Variant.Zusy.386742
AvastWin32:AdwareX-gen [Adw]
Ad-AwareGen:Variant.Zusy.386742
SophosMal/Generic-R
DrWebTrojan.MulDrop11.28728
McAfee-GW-EditionBehavesLike.Win32.Dropper.dh
EmsisoftGen:Variant.Zusy.386742 (B)
IkarusTrojan.Win32.Crypt
GDataGen:Variant.Zusy.386742
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1143574
Antiy-AVLTrojan/Win32.Kryptik
ArcabitTrojan.Zusy.D5E6B6
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win.Generic.R426052
ALYacGen:Variant.Zusy.386742
MAXmalware (ai score=87)
MalwarebytesAdware.DownloadAssistant
RisingTrojan.Kryptik!1.AA55 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HLIQ!tr
AVGWin32:AdwareX-gen [Adw]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove PUA.AgentPMF.S21238239?

PUA.AgentPMF.S21238239 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment