PUA

PUA.AgentPMF.S31839339 (file analysis)

Malware Removal

The PUA.AgentPMF.S31839339 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.AgentPMF.S31839339 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Uses Windows utilities for basic functionality
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Arabic (Egypt)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine PUA.AgentPMF.S31839339?


File Info:

name: 622AD869D12C038965B6.mlw
path: /opt/CAPEv2/storage/binaries/68b28492f64df2cd02323a20ca2de55cf5ea79dfc2924391fde7cead1dbd90a9
crc32: B1298F23
md5: 622ad869d12c038965b6498c33d0f522
sha1: 67ba5f3a5e2fcaefc245b00162baa159a584d14c
sha256: 68b28492f64df2cd02323a20ca2de55cf5ea79dfc2924391fde7cead1dbd90a9
sha512: ffb47a368e2fd47905e5fef6eecf757b6dc1d7fc1d8b2f15f7cd92037397f524272008928db60037d43200eaf603c8a24d5d750c198d658bd7e1a04c890355ef
ssdeep: 12288:9m3rwBcrb/axKMmKamTZd0171sdc9J5YWXmPa/1FfvHhku/nlq:98EBcrb/aIKxTj0odFPa/1JJrvlq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T170056C207641C03AD5B201725A6CAA6B143E7F600FB691DF97C85F7E5A789C24F31F2A
sha3_384: a6b5f1152d203c981fec3d72652bdc5c2a3c0e11fa4c89408d6b1f279c82839ff6b5f6eb3995941b2ce8a7ae75f9ac1d
ep_bytes: e8ec080000e98efeffff3b0d14104b00
timestamp: 2020-10-01 12:08:21

Version Info:

CompanyName: CasinoCom
FileDescription: CasinoCom
FileVersion: 1.1.2.1
InternalName: Installer
LegalCopyright: Copyright 2014
OriginalFilename: installer.exe
ProductName: CasinoCom
ProductVersion: 1.1.2.1
Translation: 0x0409 0x04b0

PUA.AgentPMF.S31839339 also known as:

LionicTrojan.Win32.Generic.4!c
CAT-QuickHealPUA.AgentPMF.S31839339
SkyhighBehavesLike.Win32.Dropper.bh
Cylanceunsafe
K7GWAdware ( 0059e4c11 )
K7AntiVirusAdware ( 0059e4c11 )
ESET-NOD32a variant of Win32/PlayTech.C potentially unwanted
Paloaltogeneric.ml
ClamAVWin.Trojan.Generickdz-9975504-0
SUPERAntiSpywareTrojan.Agent/GenericKDZ
SophosMal/Generic-S
GDataWin32.Application.PSE.RI54L
JiangminTrojan.Generic.gzxef
GoogleDetected
VaristW32/Trojan.GHJ.gen!Eldorado
MicrosoftTrojan:Win32/Zpevdo.B
McAfeeGenericRXAA-AA!622AD869D12C
MalwarebytesGeneric.Malware.AI.DDS
RisingTrojan.Zpevdo!8.F912 (CLOUD)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenericKDZ.7266!tr
DeepInstinctMALICIOUS

How to remove PUA.AgentPMF.S31839339?

PUA.AgentPMF.S31839339 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment