PUA

PUA.PrepscramRI.S19738760 malicious file

Malware Removal

The PUA.PrepscramRI.S19738760 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.PrepscramRI.S19738760 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

all.fingersleep.bid
none.coalrate.men

How to determine PUA.PrepscramRI.S19738760?


File Info:

crc32: 217C8F87
md5: 71807f2c43f58eaf2431c9bb21231a6b
name: 71807F2C43F58EAF2431C9BB21231A6B.mlw
sha1: b06352697c36c10cdaf9a3893da2cf45d540f106
sha256: 215c710ebfdf554fe413af8d27a58ba5b0977affe6cb6e547d4a7bea8c3cfeb5
sha512: dc014edeaf012baf3f5148f547974d7f9b32b9fbf795e230f96442303035e61d015cba42a6fa45535db5b2867f824d891cac79cb0d980b5df2a58f31ffadbc78
ssdeep: 24576:jYAgFQIzKqduxnWkIizdt7EdAxu4vebVhQI+v7jhv2alEekdeHBevwR0mDF2y6D:kAgfObnWhizj7to4vMVP+v70alhuvwR
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

PUA.PrepscramRI.S19738760 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053aa131 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealPUA.PrepscramRI.S19738760
ALYacTrojan.Agent.DCUT
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1481053
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Kryptik.1c7f6ab8
K7GWTrojan ( 0053aa131 )
Cybereasonmalicious.c43f58
CyrenW32/S-d6855570!Eldorado
SymantecAdware.IstartSurf
ESET-NOD32a variant of Win32/Kryptik.GJPW
APEXMalicious
AvastWin32:StartSurf-B [Adw]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.DCUT
NANO-AntivirusTrojan.Win32.Kryptik.fgmfok
MicroWorld-eScanTrojan.Agent.DCUT
TencentTrojan.Win32.Kryptik.gjpw
Ad-AwareTrojan.Agent.DCUT
SophosMal/Generic-S
ComodoApplication.Win32.Prepscram.GJPW@7shrn9
BitDefenderThetaGen:NN.ZexaF.34294.FzW@a8Zjf1nk
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.71807f2c43f58eaf
EmsisoftTrojan.Agent.DCUT (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Generic.ayoe
AviraHEUR/AGEN.1103317
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.280241C
MicrosoftSoftwareBundler:Win32/Prepscram
ArcabitTrojan.Agent.DCUT
SUPERAntiSpywareAdware.IStartSurf/Variant
GDataTrojan.Agent.DCUT
AhnLab-V3PUP/Win32.IStartSurf.R236922
Acronissuspicious
McAfeePUP-HEP
MAXmalware (ai score=100)
VBA32BScope.AdWare.StartSurf
MalwarebytesTrojan.IStartSurf
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.100 (RDML:EbEpVMMvUe61OsiCRlYjnw)
YandexTrojan.GenAsa!rN++fuyNZgs
IkarusTrojan-Ransom.HydraCrypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CGJG!tr
AVGWin32:StartSurf-B [Adw]
Paloaltogeneric.ml

How to remove PUA.PrepscramRI.S19738760?

PUA.PrepscramRI.S19738760 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment