PUA

PUA.Oooitservi.Gen removal

Malware Removal

The PUA.Oooitservi.Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.Oooitservi.Gen virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Unconventionial language used in binary resources: Russian
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

forces.procoldpro.ru

How to determine PUA.Oooitservi.Gen?


File Info:

crc32: 0E944F44
md5: be104691c9e50a319cf8550a35dbde1a
name: BE104691C9E50A319CF8550A35DBDE1A.mlw
sha1: fc4c06d26f25d0596710aa8ea59ec08db76d39f0
sha256: 800f8e14d8c3a0c3333789b9d0710c5550b28603fc2b598624d1240aadd43d67
sha512: 4ed2c5859deb08d87484479cedeb68e0869c68a356cec7d3d21f30faa61c247d5e67ece1a4e4e074555dfad1c5b0c5a1d72925247a7639d87f8f913085d73314
ssdeep: 12288:QNfTpzJdai/Bout92BJAbThbVnns0r7d:QNLBnai/BouDbns0r
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

PUA.Oooitservi.Gen also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
DrWebTrojan.LoadMoney.451
MicroWorld-eScanGen:Variant.Razy.787373
FireEyeGeneric.mg.be104691c9e50a31
CAT-QuickHealPUA.Oooitservi.Gen
McAfeeLoadMoney
CylanceUnsafe
ZillyaAdware.1ClickDownloadCRT.Win32.966
K7AntiVirusUnwanted-Program ( 0040f9cf1 )
K7GWAdware ( 004b31441 )
Cybereasonmalicious.1c9e50
ArcabitTrojan.Razy.DC03AD
InvinceaGeneric PUA PM (PUA)
BitDefenderThetaGen:NN.ZexaF.34634.LmX@aGITfkck
CyrenW32/Ogimant.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Kasperskynot-a-virus:Downloader.Win32.LMN.agj
BitDefenderGen:Variant.Razy.787373
NANO-AntivirusTrojan.Win32.LMN.dllcic
Ad-AwareGen:Variant.Razy.787373
EmsisoftApplication.InstallMon (A)
ComodoApplication.Win32.LoadMoney.AFF@5j5nvj
F-SecurePotentialRisk.PUA/LoadMoney.qoabn
BaiduWin32.Adware.Kryptik.e
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R06EC0PKI20
McAfee-GW-EditionLoadMoney
SophosGeneric PUA PM (PUA)
IkarusVirus.Win32.Cryptor
JiangminTrojanDropper.Agent.brlc
WebrootW32.Adware.Gen
AviraPUA/LoadMoney.qoabn
Antiy-AVLTrojan[Downloader:not-a-virus]/Win32.LMN.agj
GridinsoftTrojan.LoadMoney.sd!c
MicrosoftSoftwareBundler:Win32/Ogimant
ZoneAlarmnot-a-virus:Downloader.Win32.LMN.agj
GDataGen:Variant.Razy.787373
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Ogimant.R149213
Acronissuspicious
VBA32SScope.Downware.LMN
ALYacGen:Variant.Razy.787373
MAXmalware (ai score=85)
MalwarebytesPUP.Optional.LoadMoney
ESET-NOD32a variant of Win32/Adware.LoadMoney.AFA
TrendMicro-HouseCallTROJ_GEN.R06EC0PKI20
RisingMalware.Undefined!8.C (TFE:1:0uOwrsNHBYU)
YandexPUA.Downloader!NNJ9Wigje8s
SentinelOneStatic AI – Malicious PE
eGambitPE.Heur.InvalidSig
FortinetAdware/LoadMoney
AVGWin32:AdwareSig [Adw]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM19.1.5DB7.Malware.Gen

How to remove PUA.Oooitservi.Gen?

PUA.Oooitservi.Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment