PUA

PUA:Win32/Cain removal guide

Malware Removal

The PUA:Win32/Cain is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/Cain virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Network activity detected but not expressed in API logs
  • Installs WinPCAP
  • Anomalous binary characteristics

How to determine PUA:Win32/Cain?


File Info:

crc32: E5B19C2E
md5: ea2ef30c99ececb1eda9aa128631ff31
name: ca_setup.exe
sha1: 82407eaf6437d6956f63e85b28c0ec6ca58d298a
sha256: f98bc99cb8160d4e7f19fb76410ca4fab37c3d3dbfef6123b54c6c78d0be174c
sha512: a347f79ae64231f514d1c107db6d5ee78d820b5aec97a05af23b04c667394d60f57f5870d0e864111f68225c4c7af933e146b70621d618ad67008e632d28342a
ssdeep: 196608:ikSwsUCo2fDk4F4DulUT6qnOBqhliAi9siR6I0:bR2fg4uS6OOl26I0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x
FileDescription: Cain & Abel v4.9.56 Installation
FileVersion:
CompanyName: x

PUA:Win32/Cain also known as:

MicroWorld-eScanApplication.Agent.FQB
CAT-QuickHealHackTool.Cain
McAfeeHackTool-CainAbel
CylanceUnsafe
ZillyaTool.Cain.Win32.276
AegisLabRiskware.Win32.Cain.1!c
K7AntiVirusUnwanted-Program ( 004bf2291 )
BitDefenderApplication.Agent.FQB
K7GWUnwanted-Program ( 004bf2291 )
Cybereasonmalicious.c99ece
TrendMicroHKTL_CAIN.SPS
CyrenW32/Trojan.KISD-0167
SymantecSecurityRisk.BL
ESET-NOD32a variant of Win32/CainAbel potentially unsafe
Kasperskynot-a-virus:PSWTool.Win32.Cain.bs
AlibabaHackTool:Win32/CainAbel.21734fe5
NANO-AntivirusRiskware.Win32.Cain.ecncwa
ViRobotPSWTool.Cain.8244106
Ad-AwareApplication.Agent.FQB
EmsisoftApplication.Agent.FQB (B)
ComodoApplicUnwnt@#3u2ckdagt5z78
DrWebTool.Cain.116
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionHackTool-CainAbel
MaxSecureTrojan.Malware.7045501.susgen
FireEyeApplication.Agent.FQB
IkarusPUA.CainAbel
F-ProtW32/Trojan5.OVO
WebrootPua.Downloadmanager
FortinetRiskware/Cain
ArcabitApplication.Agent.FQB
ZoneAlarmnot-a-virus:PSWTool.Win32.Cain.bs
MicrosoftPUA:Win32/Cain
AhnLab-V3HackTool/Win32.CainAbel.C1190241
MAXmalware (ai score=100)
TrendMicro-HouseCallHKTL_CAIN.SPS
RisingMalware.Undefined!8.C (CLOUD)
YandexRiskware.PSWTool!
eGambitGeneric.Malware
GDataApplication.Agent.FQB
Paloaltogeneric.ml

How to remove PUA:Win32/Cain?

PUA:Win32/Cain removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment