PUA

PUA.WacapewPMF.S18512993 removal

Malware Removal

The PUA.WacapewPMF.S18512993 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.WacapewPMF.S18512993 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (8 unique times)
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
accounts.youtube.com
www.gstatic.com
ssl.gstatic.com

How to determine PUA.WacapewPMF.S18512993?


File Info:

crc32: D40D4448
md5: c3f16fb026ed9067d2689b98fbb886e0
name: C3F16FB026ED9067D2689B98FBB886E0.mlw
sha1: 0a3d5215e9b4d60e99af16bd7f700e63205dbf4b
sha256: decadc467c1623914be3d47ef782a5a7e3d8da0a026b181e309b027b83708982
sha512: 9b9493ac72e64182b86587585752ec14460fec7e6398cb249295b01449fd00297d450aaf633d53526405acd19b76caf8873df261b33666d5000bb18c862fa74b
ssdeep: 6144:yzgHui58ohKgxag1ED2BT1k6kLhLOaow:9HjSohKgx7jd4Lhyar
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

PUA.WacapewPMF.S18512993 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005378b01 )
LionicRiskware.Win32.Generic.1!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader26.55672
CynetMalicious (score: 100)
CAT-QuickHealPUA.WacapewPMF.S18512993
ALYacGen:Variant.Razy.873682
CylanceUnsafe
ZillyaAdware.AdposhelGen.Win32.5
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaAdWare:Win32/Adposhel.648a3304
K7GWTrojan ( 005378b01 )
Cybereasonmalicious.026ed9
CyrenW32/S-8e8a1e4c!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Adposhel.CG
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
ClamAVWin.Trojan.Agent-6942940-1
Kasperskynot-a-virus:AdWare.Win32.Adposhel.ovsm
BitDefenderGen:Variant.Razy.873682
NANO-AntivirusTrojan.Win32.Adposhel.fiaobz
ViRobotTrojan.Win32.Adposhel.Gen.C
MicroWorld-eScanGen:Variant.Razy.873682
TencentMalware.Win32.Gencirc.10b0d017
Ad-AwareGen:Variant.Razy.873682
SophosAdposhel (PUA)
ComodoApplication.Win32.AdWare.Adposhel.BD@7qel9k
BitDefenderThetaAI:Packer.8EAD14551E
McAfee-GW-EditionBehavesLike.Win32.Generic.tz
FireEyeGeneric.mg.c3f16fb026ed9067
EmsisoftGen:Variant.Razy.873682 (B)
SentinelOneStatic AI – Malicious PE
AviraADWARE/Adware.Gen8
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASBOL.C4F4
MicrosoftTrojan:Win32/Wacatac.A!ml
SUPERAntiSpywareAdware.Adposhel/Variant
GDataGen:Variant.Razy.873682
AhnLab-V3Adware/Win32.Adposhel.R242988
Acronissuspicious
McAfeeAdware-Adposhel
MAXmalware (ai score=93)
VBA32BScope.Malware-Cryptor.Kidep
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
RisingAdware.Adposhel!1.B313 (CLASSIC)
YandexTrojan.GenAsa!/4w1M3a6VoI
IkarusPUA.Adposhel
MaxSecureTrojan.razy.359339
FortinetAdware/Adposhel
AVGWin32:AdwareX-gen [Adw]
Paloaltogeneric.ml

How to remove PUA.WacapewPMF.S18512993?

PUA.WacapewPMF.S18512993 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment