PUA

PUA:Win32/Avarus removal guide

Malware Removal

The PUA:Win32/Avarus is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/Avarus virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
installer.ppdownload.com
a.tomx.xyz

How to determine PUA:Win32/Avarus?


File Info:

crc32: 6CB05023
md5: 8529ad4cc6853ed95a4c847ab993f7f6
name: multiplicationtablesetup.exe
sha1: 0e4be463b5bfa377c2bae6b669dd5ae29b9d3f6c
sha256: 3f64f8393754d52e8c430717d9673164535c474dedccaf550516c9eb49865297
sha512: 4976d8f9ecef5742401338b29ca1f6b6ea23051bdf020c95d47087fd87c02872075437e36d97b7ca42e6fbb07667c23346766865a32a83e422f0a186121ec010
ssdeep: 12288:OE2ArFBW4zcfmQT5XxrxuiABXpf3PKk9hxsesWj7TlalYAyBMJ3:OE3rFB5jK5XdlAbfXhllalhyat
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: RSpark
CompanyName: Multiplication Table
LegalTrademarks: Multiplication Table
Comments: Multiplication Table
ProductName: Multiplication Table
ProductVersion: 3.0
FileDescription: Quickly create easy to use and easy to print multiplication tables from you computer
Translation: 0x0000 0x04e4

PUA:Win32/Avarus also known as:

BkavW32.HfsAdware.A935
DrWebTrojan.OutBrowse.1014
MicroWorld-eScanApplication.Bundler.Outbrowse.F
FireEyeApplication.Bundler.Outbrowse.F
CAT-QuickHealTrojanDownloader.NSIS.OutBrow
CylanceUnsafe
VIPREOutBrowse (fs)
AegisLabRiskware.NSIS.OutBrowse.1!c
SangforMalware
K7AntiVirusAdware ( 0055c2341 )
BitDefenderApplication.Bundler.Outbrowse.F
K7GWAdware ( 0055c2341 )
Cybereasonmalicious.cc6853
Invinceaheuristic
SymantecTrojan.Gen.MBT
TotalDefenseWin32/Tnega.XAWT!suspicious
APEXMalicious
GDataWin32.Application.Outbrowse.X
Kasperskynot-a-virus:Downloader.NSIS.OutBrowse.a
AlibabaDownloader:Win32/OutBrowse.dd8c95d3
NANO-AntivirusTrojan.Win32.Adw.ctrgoq
ViRobotAdware.Outbrowse.587125
RisingAdware.Outbrowse!1.A0B6 (CLASSIC)
EmsisoftApplication.Bundler.Outbrowse.F (B)
ComodoApplicUnwnt@#1jyt9wdbsrzly
F-SecureApplication:W32/Outbrowse
BaiduNSIS.Adware.Generic.a
McAfee-GW-EditionNSIS/Outbrowse.a
Trapminemalicious.moderate.ml.score
IkarusAdWare
JiangminAdWare/OutBrowse.a
WebrootPua.Outbrowse
AviraPUA/Outbrowse.Gen
MAXmalware (ai score=100)
Antiy-AVLGrayWare[Downloader]/Win32.Adload.gen
Endgamemalicious (high confidence)
ArcabitApplication.Bundler.Outbrowse.F
SUPERAntiSpywarePUP.OutBrowse/Variant
ZoneAlarmnot-a-virus:Downloader.NSIS.OutBrowse.a
MicrosoftPUA:Win32/Avarus
Acronissuspicious
McAfeeArtemis!8529AD4CC685
VBA32Downloader.OutBrowse
MalwarebytesPUP.Optional.OutBrowse
ESET-NOD32Win32/OutBrowse.D potentially unwanted
YandexPUA.OutBrowse!
SentinelOneDFI – Suspicious PE
eGambitGeneric.Downloader
FortinetRiskware/NSIS_OutBrowse
AVGFileRepMetagen [Adw]
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Generic/Virus.Downloader.464

How to remove PUA:Win32/Avarus?

PUA:Win32/Avarus removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment