PUA

About “PUAAdvertising:Win32/Shoppers” infection

Malware Removal

The PUAAdvertising:Win32/Shoppers is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUAAdvertising:Win32/Shoppers virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine PUAAdvertising:Win32/Shoppers?


File Info:

crc32: 7CF82FCD
md5: fe32b8b13a94dd17ed4a5e7ab0cd9cd8
name: FE32B8B13A94DD17ED4A5E7AB0CD9CD8.mlw
sha1: 89ae49e9c51388000ce19b93d32ee129c1d8c4bf
sha256: 8503061e8f4db42566833211edb4aacc321984e84499b039e7d55306318d36a6
sha512: 08b87ce3d7f0fb4cd94b0b446565a9e4c7747543130d9edb1e193cf80dffe592cb4220a13b2f556da67986fe462841d62cb07af5910d4fc0bd9e113ab86337a9
ssdeep: 6144:DajXWRHgre+gAk0UCa25wBol3Kh0W1SEyVm2BYKAtC7RRDPs45y6VR0b:DLqgAkOa24GRLmKAARDbVRk
type: MS-DOS executable, MZ for MS-DOS

Version Info:

0: [No Data]

PUAAdvertising:Win32/Shoppers also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
Cybereasonmalicious.9c5138
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.HAMZRNX
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Downloader.Win32.Cridex.ojc
BitDefenderTrojan.GenericKD.37911268
MicroWorld-eScanTrojan.GenericKD.37911268
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34236.yu1@am!Swxdi
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.fe32b8b13a94dd17
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/AD.GenSteal.ubmfm
eGambitPE.Heur.InvalidSig
KingsoftWin32.TrojDownloader.Cridex.o.(kcloud)
MicrosoftPUAAdvertising:Win32/Shoppers
GDataWin32.Trojan-Stealer.CoinStealer.YV9HHX
McAfeeArtemis!FE32B8B13A94
MAXmalware (ai score=80)
IkarusWin32.Outbreak
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGFileRepMalware
Paloaltogeneric.ml

How to remove PUAAdvertising:Win32/Shoppers?

PUAAdvertising:Win32/Shoppers removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment