PUA

How to remove “PUA.ObfuscatedPMF.S31670779”?

Malware Removal

The PUA.ObfuscatedPMF.S31670779 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.ObfuscatedPMF.S31670779 virus can do?

  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Overwrites local Administrator password
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine PUA.ObfuscatedPMF.S31670779?


File Info:

name: 469EAA55487BFA6C9BD6.mlw
path: /opt/CAPEv2/storage/binaries/0f33027204396b875e6869f3e3ad95c95e42dac25524d725185db2f96754ef3a
crc32: 9DD3DB6A
md5: 469eaa55487bfa6c9bd6414bb72cb9ab
sha1: 00fb8ac3a1bb0ce3d732f16f816dd61cf6e7c261
sha256: 0f33027204396b875e6869f3e3ad95c95e42dac25524d725185db2f96754ef3a
sha512: 57011f75d51f076c471f3eef19ce1e28a5751a56ef6766d15ed5327e15da999e7611f49039edfac5185b0d81a34632a7d912275e6c79696dbf7248458947415c
ssdeep: 1536:R97fbN3eEDhDPA/pICdUkbBtW7upvaLU0bI5taxKo0IOlnToIfhwp8Oy:Rp7DhdC6kzWypvaQ0FxyNTBfhGS
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1AA936D41F3E202F7E6F2053100A6762FD73662389764A8EBC74C3D529913AD5A63D3E9
sha3_384: 7ba26eee5507eb9d1771c0c8e4ec726c3b82c38eac1b0fad1dab6e8194b26b76e88836897c92b59fdb979c7ef8d97270
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2019-07-30 08:52:45

Version Info:

0: [No Data]

PUA.ObfuscatedPMF.S31670779 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.72210904
FireEyeGeneric.mg.469eaa55487bfa6c
CAT-QuickHealPUA.ObfuscatedPMF.S31670779
SkyhighBehavesLike.Win32.Generic.mh
ALYacTrojan.GenericKD.72210904
Cylanceunsafe
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Kryptik.90c70ca6
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002H0CD124
ClamAVWin.Trojan.Generic-10011119-0
BitDefenderTrojan.GenericKD.72210904
AvastWin32:Evo-gen [Trj]
EmsisoftTrojan.GenericKD.72210904 (B)
VIPRETrojan.GenericKD.72210904
SophosGeneric ML PUA (PUA)
MAXmalware (ai score=81)
GDataTrojan.GenericKD.72210904
GoogleDetected
VaristW32/Kryptik.AYO.gen!Eldorado
ArcabitTrojan.Generic.D44DD9D8
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
MalwarebytesGeneric.Malware/Suspicious
RisingTrojan.Agent!8.B1E (RDMK:cmRtazqfvP9nXxQqBUWQaskR3ZLN)
IkarusTrojan.Win32.Occamy
MaxSecureTrojan.Malware.187905819.susgen
FortinetW32/Nitol.AB!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Jatommy

How to remove PUA.ObfuscatedPMF.S31670779?

PUA.ObfuscatedPMF.S31670779 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment