PUA

PUA:Win32/DomaIQ removal guide

Malware Removal

The PUA:Win32/DomaIQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/DomaIQ virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine PUA:Win32/DomaIQ?


File Info:

name: DC7AA3E947D80D2C419B.mlw
path: /opt/CAPEv2/storage/binaries/3a261b2b3ee0558bceab3743e67fae10db8479ad45810588331fc610a02e51f9
crc32: 65587858
md5: dc7aa3e947d80d2c419ba50cbfc5356e
sha1: ca1abfb142d2db943b06258849adbcee2edfb348
sha256: 3a261b2b3ee0558bceab3743e67fae10db8479ad45810588331fc610a02e51f9
sha512: 89102f5243b3ab0fa98a43b825807c3f1cc39379a60dd204f975442ad3cdc1487b0c2a43756ac7595b6dc9f1637a0d92d129718d2b4cbde2ff227735ac26c9e9
ssdeep: 3072:8w59zbeCBy2+pzSKjJTpxznMe94t6K2z6xREV8Gf8Cg8NDOOOOX+z+Q+4Zn2WVGd:8w59zbeEKSK1ThcBZXrtCw+S1C
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T109548D1034CA8170E57383725519991107BA7E625F70EAEF2BE8BD0E2BB75E19335B32
sha3_384: 068e58a1551a85b129e6af7b66b7dad7f5d6ad0309dcd581f1b6ba0f950473119c4e7d259d50db4ffe11718b27fff824
ep_bytes: e86a3b0000e939feffff558bec837d08
timestamp: 2014-06-17 10:17:30

Version Info:

0: [No Data]

PUA:Win32/DomaIQ also known as:

BkavW32.AIDetectMalware
LionicAdware.MSIL.Generic.lZ0B
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Graftor.312002
FireEyeGeneric.mg.dc7aa3e947d80d2c
SkyhighBehavesLike.Win32.Generic.dh
McAfeeGenericRXAA-AA!DC7AA3E947D8
Cylanceunsafe
ZillyaAdware.DomaIQ.Win32.5050
SangforSuspicious.Win32.Save.a
K7AntiVirusAdware ( 004b9d501 )
K7GWAdware ( 004b9d501 )
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderThetaGen:NN.ZexaF.36744.rmW@aST@Fuai
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/DomaIQ.BB potentially unwanted
APEXMalicious
CynetMalicious (score: 99)
Kasperskynot-a-virus:VHO:AdWare.MSIL.DomaIQ.gen
BitDefenderGen:Variant.Graftor.312002
SUPERAntiSpywarePUP.DomaIQ/Variant
AvastWin32:Malware-gen
TencentAdware.Win32.Domaiq.ya
SophosGeneric Reputation PUA (PUA)
F-SecureTrojan.TR/Inject.owlpanom
VIPREGen:Variant.Graftor.312002
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Graftor.312002 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Graftor.312002
VaristW32/DomaIQ.Y.gen!Eldorado
AviraTR/Inject.owlpanom
Antiy-AVLGrayWare/Win32.DomaIQ.bh
Kingsoftmalware.kb.a.1000
XcitiumApplication.Win32.DomaIQ.XFR@5bgelt
ArcabitTrojan.Graftor.D4C2C2
ZoneAlarmnot-a-virus:VHO:AdWare.MSIL.DomaIQ.gen
MicrosoftPUA:Win32/DomaIQ
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R499432
Acronissuspicious
ALYacGen:Variant.Graftor.312002
MAXmalware (ai score=80)
MalwarebytesGeneric.Malware.AI.DDS
RisingTrojan.DL.Win32.Tugspay.l (CLASSIC)
IkarusTrojan.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/DomaIQ
AVGWin32:Malware-gen
Cybereasonmalicious.142d2d
DeepInstinctMALICIOUS

How to remove PUA:Win32/DomaIQ?

PUA:Win32/DomaIQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment