PUA

PUA:Win32/Amonetize (file analysis)

Malware Removal

The PUA:Win32/Amonetize is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/Amonetize virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine PUA:Win32/Amonetize?


File Info:

crc32: BC335531
md5: b105c3416d59ae71f0feee5debdc7a0c
name: 46a1edc4a43a628f455f7e0cd46876cf.exe
sha1: d7f0e642c9f15a2a022ed426f56852dfd7261188
sha256: add006ef05ba765d1de2efc5574c3ea2acfa1401f0dd7ac671cd7234bafb7f24
sha512: 74f52b806ba9a3fe54df81a0f1b939a170493a03729f81819587af6ee983427ba5e862ad4fcf96d2cb0b4abb83fcaa188c8fe81ee991995282b8140c6d492a21
ssdeep: 98304:8M2K8bvc+DdudV77au7fFRe5nN9c0d7ETTM:LBMfumGqJNaHv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0804 0x04b0
LegalCopyright: x6280x672fx652fx6301(http://www.hofosoft.com)
Assembly Version: 1.2.0.0
InternalName: x5965x9e4fx7f51x6559x4f5cx4e1ax7b54x9898x52a9x624b
FileVersion: 1.2.0.0
CompanyName: x6280x672fx652fx6301(http://www.hofosoft.com)
Comments: x5965x9e4fx7f51x6559x4f5cx4e1ax7b54x9898x52a9x624bx662fx4e00x6b3ex5965x9e4fx7f51x7edcx6559x80b2x5b66x4e60x5e73x53f0x4f5cx4e1ax8f85x52a9x7b54x9898x8f6fx4ef6xff0cx53efx4ee5x5b9ex73b0x624bx52a8x6216x81eax52a8x7684x4f5cx4e1ax7b54x9898
ProductName: x5965x9e4fx7f51x6559x4f5cx4e1ax7b54x9898x52a9x624b
ProductVersion: 1.2.0.0
FileDescription: x5965x9e4fx7f51x6559x4f5cx4e1ax7b54x9898x52a9x624bx662fx4e00x6b3ex5965x9e4fx7f51x7edcx6559x80b2x5b66x4e60x5e73x53f0x4f5cx4e1ax8f85x52a9x7b54x9898x8f6fx4ef6xff0cx53efx4ee5x5b9ex73b0x624bx52a8x6216x81eax52a8x7684x4f5cx4e1ax7b54x9898
OriginalFilename: x5965x9e4fx7f51x6559x4f5cx4e1ax7b54x9898x52a9x624b

PUA:Win32/Amonetize also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Bulz.37730
FireEyeGeneric.mg.b105c3416d59ae71
CAT-QuickHealTrojan.Amonetize
Qihoo-360Win32/Virus.Adware.6e5
McAfeeArtemis!B105C3416D59
CylanceUnsafe
AegisLabAdware.Win32.HofoSoft.2!c
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Bulz.37730
K7GWRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZexaF.34196.wx3@aCEv!Wgj
CyrenW32/Application.EZTT-4355
SymantecML.Attribute.HighConfidence
APEXMalicious
Kasperskynot-a-virus:HEUR:AdWare.Win32.HofoSoft.gen
ViRobotAdware.Hofosoft.3512262
RisingPUA.Amonetize!8.C5 (CLOUD)
ZillyaAdware.HofoSoft.Win32.4
SophosGeneric PUA NH (PUA)
IkarusAdWare.InstallBrain
MAXmalware (ai score=89)
Antiy-AVLGrayWare[AdWare]/Win32.HofoSoft
MicrosoftPUA:Win32/Amonetize
ArcabitTrojan.Bulz.D9362
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.HofoSoft.gen
GDataGen:Variant.Bulz.37730
AhnLab-V3Malware/Win32.Generic.C4181852
VBA32suspected of Trojan.Downloader.gen.h
ALYacGen:Variant.Bulz.37730
TrendMicro-HouseCallTROJ_GEN.R002H09HC20
FortinetAdware/HofoSoft
MaxSecureTrojan.Malware.77092960.susgen

How to remove PUA:Win32/Amonetize?

PUA:Win32/Amonetize removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment