PUA

PUA:Win32/AdvPcTweak removal tips

Malware Removal

The PUA:Win32/AdvPcTweak is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/AdvPcTweak virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine PUA:Win32/AdvPcTweak?


File Info:

name: 961A27661AE554E4445E.mlw
path: /opt/CAPEv2/storage/binaries/005beacf097aa0bf413d2f473a86c0c4e003eb77d1f4a3b1e9859ef3ddf719c0
crc32: DA9E8434
md5: 961a27661ae554e4445e694bd2f5f2fe
sha1: 0e4044d67e1e36dfc2eda88cdcd5021398b5bdba
sha256: 005beacf097aa0bf413d2f473a86c0c4e003eb77d1f4a3b1e9859ef3ddf719c0
sha512: d0b0d91425f7d83d5947e9a383451a5ce79f738c796ad659b72bb6df161eef8566dad707fe1db8ece2caff4aa7ef295d561b9a8473fbc962ccadd9cc5f62fa50
ssdeep: 196608:La9sHgc9UScXtVqKEFWBQZRxVAJPM/YIRW:UsHg5ScXq5FnLAqM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16D6633A85361D559DAF2D23DCC7F2061671BDEEE8A34920F684A7251237A03CDF19B23
sha3_384: 4371eb68ffc16d3e248e1291a3ae1852bc86e132db62b6ff8a0413d05e9df7d8739e01a5eaa3ad8559764072cc0bde97
ep_bytes: 9c60685374416c685468496ee8000000
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName:
FileDescription:
FileVersion: 6.3.3.8
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 6.3.3.8
Comments:
ThinstallLicense: Internal development license
ThinstallVersion: 3.358
Translation: 0x0409 0x04e4

PUA:Win32/AdvPcTweak also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
FireEyeGeneric.mg.961a27661ae554e4
SkyhighArtemis
Cylanceunsafe
Cybereasonmalicious.67e1e3
DrWebProgram.Unwanted.1087
Trapminesuspicious.low.ml.score
JiangminTrojanDownloader.Adload.idz
VaristW32/Backdoor.JUDH-3136
XcitiumTrojWare.Win32.Banbra.rh@4kvwju
MicrosoftPUA:Win32/AdvPcTweak
GoogleDetected
McAfeeArtemis!961A27661AE5
MAXmalware (ai score=94)
RisingTrojan.Generic@AI.100 (RDML:4BJrttFg5gtFTObYmWi7hQ)
YandexBackdoor.Agent!Q5OR3Fj6m7Y
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_60% (W)

How to remove PUA:Win32/AdvPcTweak?

PUA:Win32/AdvPcTweak removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment