PUA

Should I remove “PUA.WacatacFC.S18876034”?

Malware Removal

The PUA.WacatacFC.S18876034 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.WacatacFC.S18876034 virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine PUA.WacatacFC.S18876034?


File Info:

crc32: B80B10A5
md5: f4f7d06ca24f85662d1b081db452d6d6
name: F4F7D06CA24F85662D1B081DB452D6D6.mlw
sha1: 019d4cb28f01f644c7656235cd0a43bb69306ddf
sha256: 4380a8cc9e019dcaf2ae7eaefee0abd39b4156f2a66a5f7c969be6b17bcdc3e4
sha512: fe6b6b81d04c7f74e5a6db740c498f61b8f9a3ce2e9fbec97ca9ffc53a370d0270463a5e31254b09bd138dafd23acb84c186113445f40c3fb691d0470da2daec
ssdeep: 384:FNPAotHJr3FN3tPo5aC15pKJmXyMqIhUwDkW4yu/bEX0sF68c2jEWFWHpW:FNRHJr3FN3tPWfU8XyMq654y9F79EWK
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: MSPAINT
FileVersion: 6.3.9600.17415 (winblue_r4.141028-1500)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.3.9600.17415
FileDescription: Paint
OriginalFilename: MSPAINT.EXE
Translation: 0x0409 0x04b0

PUA.WacatacFC.S18876034 also known as:

K7AntiVirusTrojan-Downloader ( 005773691 )
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen11.62018
CynetMalicious (score: 100)
CAT-QuickHealPUA.WacatacFC.S18876034
ALYacIL:Trojan.MSILZilla.1794
CylanceUnsafe
ZillyaDownloader.Seraph.Win32.330
SangforTrojan.Win32.Wacatac.B
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:MSIL/Seraph.f27cc1a6
K7GWTrojan-Downloader ( 005773691 )
Cybereasonmalicious.ca24f8
CyrenW32/MSIL_Kryptik.DHR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.HHX
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Dropper.Wacatac-9835373-0
KasperskyHEUR:Trojan-Downloader.MSIL.Seraph.gen
BitDefenderIL:Trojan.MSILZilla.1794
NANO-AntivirusTrojan.Win32.Seraph.ilyucw
MicroWorld-eScanIL:Trojan.MSILZilla.1794
TencentMsil.Trojan-downloader.Seraph.Efkp
Ad-AwareIL:Trojan.MSILZilla.1794
SophosML/PE-A
BitDefenderThetaGen:NN.ZemsilF.34266.zn3@aedfM1ji
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PKF21
McAfee-GW-EditionPWS-FCXH!F4F7D06CA24F
FireEyeGeneric.mg.f4f7d06ca24f8566
EmsisoftIL:Trojan.MSILZilla.1794 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.MSIL.zku
AviraHEUR/AGEN.1141492
Antiy-AVLTrojan/Generic.ASMalwS.3173EF9
MicrosoftTrojan:Win32/AgentTesla!ml
GDataIL:Trojan.MSILZilla.1794
AhnLab-V3Malware/Gen.RL_Reputation.C4331974
McAfeePWS-FCXH!F4F7D06CA24F
MAXmalware (ai score=85)
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.Quasar
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0PKF21
IkarusTrojan-Downloader.MSIL.Small
FortinetMSIL/Small.CKP!tr.dldr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove PUA.WacatacFC.S18876034?

PUA.WacatacFC.S18876034 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment