PUA

PUA:Win32/GameMiner removal instruction

Malware Removal

The PUA:Win32/GameMiner is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/GameMiner virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine PUA:Win32/GameMiner?


File Info:

name: 83AA28D15BFA00351311.mlw
path: /opt/CAPEv2/storage/binaries/d8d52ecc16496188b7b8f2af02974f0d57e63fb0559503dfe939bd722ac424e8
crc32: 26A12196
md5: 83aa28d15bfa0035131130dbf5ab94b6
sha1: 117331c27ae53baa2b52cd9617cebc5556bd617c
sha256: d8d52ecc16496188b7b8f2af02974f0d57e63fb0559503dfe939bd722ac424e8
sha512: 2a8e348a07783b39caaac54d2894d47f5029cbc8fde9f2ff9ed050cd2169347f5d48088fd3dd8cb1e7b9746f89be634ffe0033575dcd32d8e4a1dfe0f1cc911d
ssdeep: 49152:zPWI/7/tmlJdnj0Ofbeuiuae8sNxPsoVwI1HoGDCrnNsKvjfEZ9ZzTjQSie6djoY:bX74fbeq8ceoVwIKGGrnB7fsyTZNogJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EB063347BE32674CE1E170F8CE966D88F9469D20940D6BBBD40966483CEA2F1F3C5762
sha3_384: 925cc80e5d59b65c30acd7a61050c3783e688768036abc1aed3ec1733b6c1955a22181026ea6895d0a820dad018452f2
ep_bytes: b8447595005064ff3500000000648925
timestamp: 2013-04-18 06:50:07

Version Info:

Comments: RD9QA8wf
CompanyName: IfWs4Wj7
FileDescription: 2FGTWZiO
FileVersion: WPkdRAkR
InternalName: 0ajnqllV
ProductVersion: UkDxlsnZ
Translation: 0x0804 0x04b0

PUA:Win32/GameMiner also known as:

MicroWorld-eScanGen:Variant.Babar.414297
ArcabitTrojan.Babar.D65259
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
KasperskyVHO:Trojan-Dropper.Win32.Convagent.gen
BitDefenderGen:Variant.Babar.414297
EmsisoftGen:Variant.Babar.414297 (B)
FireEyeGeneric.mg.83aa28d15bfa0035
SophosMal/VMProtBad-A
GoogleDetected
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.FlyStudio.a
Kingsoftmalware.kb.a.996
MicrosoftPUA:Win32/GameMiner
ZoneAlarmVHO:Trojan-Dropper.Win32.Convagent.gen
GDataGen:Variant.Babar.414297
VaristW32/Trojan.IRG.gen!Eldorado
YandexTrojan.GenAsa!bGWspYTQKbk
IkarusRootkit.Win32.Agent
FortinetW32/Virut.CE.AVEN
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_60% (D)

How to remove PUA:Win32/GameMiner?

PUA:Win32/GameMiner removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment