PUA

What is “PUA.BitcoinminerPMF.S17319620”?

Malware Removal

The PUA.BitcoinminerPMF.S17319620 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.BitcoinminerPMF.S17319620 virus can do?

  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs

How to determine PUA.BitcoinminerPMF.S17319620?


File Info:

crc32: D1C9A075
md5: c1ecf35c35a89317f775baac4be55808
name: C1ECF35C35A89317F775BAAC4BE55808.mlw
sha1: a593c645c40ee6040466bbf08d63181410d2017a
sha256: 23c7d0054a471064681b7844ab89b34184c861739450f7aa614a9b6211897b1a
sha512: 7e45010ce065b84ea4c46464436e18229bd52c2247481e30257e281e586d1bdb56e38f03b009d77a2c17a19bc4f1f8f05148d897e56f1dac404010862f95893b
ssdeep: 768:TRksl4gjbnZa8oeZMUYO4SmiZkXfQ/NGYwT5WPMsJ11Okz5sdauKqFAmetnbcuy:TRkq4IrZntb4tGkX4N8C7RTupCnouy8
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Mark Hamilton
FileVersion: 0.0.0.1
ProductName: OBS Quickstart
ProductVersion: 0.0.0.1
FileDescription: Quickstarts OBS in portable mode
OriginalFilename: OBS Quickstart
Translation: 0x0000 0x04e4

PUA.BitcoinminerPMF.S17319620 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0051918e1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebBackDoor.Xtreme.38
ClamAVWin.Malware.Xtrat-6913730-0
CAT-QuickHealPUA.BitcoinminerPMF.S17319620
McAfeeArtemis!C1ECF35C35A8
K7GWTrojan ( 0051918e1 )
Cybereasonmalicious.c35a89
CyrenW32/Agent.BJD.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
TencentMalware.Win32.Gencirc.10ceb234
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.pc
FireEyeGeneric.mg.c1ecf35c35a89317
SentinelOneStatic AI – Malicious PE
JiangminRiskTool.Script.it
eGambitUnsafe.AI_Score_73%
MicrosoftTrojan:Script/Phonzy.A!ml
GDataWin32.Trojan.PSE.ECZJ7Q
TACHYONTrojan/W32.Agent.88576.XX
MAXmalware (ai score=99)
MalwarebytesMalware.AI.818123338
IkarusBackdoor.Xtreme
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove PUA.BitcoinminerPMF.S17319620?

PUA.BitcoinminerPMF.S17319620 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment