PUA

PUA:Win32/Bitrepeyp.C removal instruction

Malware Removal

The PUA:Win32/Bitrepeyp.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/Bitrepeyp.C virus can do?

  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup

Related domains:

z.whorecord.xyz
a.tomx.xyz
rl.ammyy.com

How to determine PUA:Win32/Bitrepeyp.C?


File Info:

crc32: 9DCC5CEA
md5: bae3b461b2ec58e3dce8bbb3748b2a80
name: suporte.exe
sha1: b0502a941fe1ba7c88c03edf1c0ab403adcf0ec2
sha256: 2c782411061687b44a78f99563d5512dab13e3f48d402916e54ced78cf96cb72
sha512: 6c66b146072c437557dd3667bc6ddf265aa276f1ae44ddeddce6edec1b418858262f2e48b30709bd9d69bc6e7685721a5a3bcfaff8d334ca17d2c0bcf73c4589
ssdeep: 12288:OVFUEuNmwvGrw9i0aTGRGicBckyyFRtWY1i3FTsvOVmzgU:UUEUUw9RaTNicBrPFRtJ1iVTsZM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 A Company. All rights reserved.
InternalName: Hetec Solutions
FileVersion: 1.0.0.0
CompanyName: Hetec Solutions
ProductName: Hetec Solutions
ProductVersion: 1.0.0.0
FileDescription: Hetec Solutions
OriginalFilename: Hetec Solutions
Translation: 0x0409 0x04b0

PUA:Win32/Bitrepeyp.C also known as:

FireEyeGeneric.mg.bae3b461b2ec58e3
Qihoo-360Win32/Virus.RemoteAdmin.3ab
VIPRERemote-Access.Win32.Ammyy (not malicious)
SangforMalware
K7AntiVirusUnwanted-Program ( 004d38111 )
BitDefenderApplication.RemoteAdmin.RIN
K7GWUnwanted-Program ( 004d38111 )
Cybereasonmalicious.1b2ec5
Invinceaheuristic
F-ProtW32/RemoteAdmin.Ammyy
SymantecTrojan.Gen.6
APEXMalicious
Paloaltogeneric.ml
GDataWin32.Riskware.RemoteAdmin.A
Kasperskynot-a-virus:RemoteAdmin.Win32.Ammyy.wrj
AlibabaRiskWare:Win32/Ammyy.88059a13
NANO-AntivirusRiskware.Win32.AmmyAdmin.dskdxp
AegisLabRiskware.Win32.Ammyy.1!c
Ad-AwareApplication.RemoteAdmin.RIN
SophosGeneric PUA LA (PUA)
ComodoMalware@#2f3x739in6xn4
DrWebProgram.RemoteAdmin.875
TrendMicroTROJ_GEN.R002C0OIR19
McAfee-GW-EditionBehavesLike.Win32.RemAdmAmmyy.bh
Trapminemalicious.high.ml.score
EmsisoftApplication.RemoteAdmin.RIN (B)
CyrenW32/RemoteAdmin.ACSY-7276
JiangminRemoteAdmin.Ammyy.bm
WebrootW32.Ammyy.Ra
MAXmalware (ai score=99)
Endgamemalicious (high confidence)
ArcabitApplication.RemoteAdmin.RIN
ZoneAlarmnot-a-virus:RemoteAdmin.Win32.Ammyy.wrj
MicrosoftPUA:Win32/Bitrepeyp.C
Acronissuspicious
McAfeeRemAdm-Ammyy
ZonerTrojan.Win32.39604
ESET-NOD32a variant of Win32/RemoteAdmin.Ammyy.B potentially unsafe
TrendMicro-HouseCallTROJ_GEN.R002C0OIR19
RisingTrojan.Generic@ML.100 (RDMK:FsBAohySly1YXfn2RrAddg)
YandexRiskware.RemoteAdmin!
SentinelOneDFI – Malicious PE
eGambitRAT.Ammyy
FortinetRiskware/Ammyy
AVGFileRepMalware [PUP]
PandaTrj/CI.A
MaxSecureTrojan.Malware.8497872.susgen

How to remove PUA:Win32/Bitrepeyp.C?

PUA:Win32/Bitrepeyp.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment