PUA

How to remove “PUA:Win32/Gemius”?

Malware Removal

The PUA:Win32/Gemius is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/Gemius virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine PUA:Win32/Gemius?


File Info:

name: B1EA73DB101443995F49.mlw
path: /opt/CAPEv2/storage/binaries/44170fdf64351206f01a6894ef54daa2122aaf9762288fac3aaebee6aa95dad4
crc32: D1F0CFDB
md5: b1ea73db101443995f494e35111c5dce
sha1: 02e35286775ec34bdf7a2756b91d6762b54a631d
sha256: 44170fdf64351206f01a6894ef54daa2122aaf9762288fac3aaebee6aa95dad4
sha512: ce0ae83ffea00e6570ffdf1ec343bb91851889fec18812293a0b19a5d25a4289d6fbcfd047866a040eb1422268aa323c402b084287e200970ef1810876f65424
ssdeep: 49152:81OsSHylzkGghSyjjw5idiC3zv4R+ch8ETmh75dSBYcjvBPqQxmTmyyDpU3:81OVsISyj3iCzeQh7xRgmk9U3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T136C5331175E0C0B2D8224C3FEA96AB5143B9E9552E20987327DAF5BC2D3ECE4C13567B
sha3_384: b5b8b795a7124d11b541b63506c1554d92460e4093547cdc1e0533ae142595312dff2535e507031b95837e1ff7486ce5
ep_bytes: 558bec6aff68e0b94100682c4a410064
timestamp: 2010-11-18 16:27:35

Version Info:

CompanyName: Gemius
FileDescription: NetPanel
FileVersion:
InternalName:
LegalCopyright:
OriginalFilename:
ProductName: NetPanel
ProductVersion:
Translation: 0x0409 0x04b0

PUA:Win32/Gemius also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Gemius.4!c
MicroWorld-eScanTrojan.Generic.34700691
FireEyeTrojan.Generic.34700691
SkyhighArtemis!Trojan
McAfeeArtemis!B1EA73DB1014
Cylanceunsafe
SangforPUP.Win32.Agent.Vjfy
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
VirITTrojan.Win32.Webpick.OOE
SymantecTrojan.Gen.MBT
BitDefenderTrojan.Generic.34700691
AvastWin32:PUP-gen [PUP]
EmsisoftTrojan.Generic.34700691 (B)
DrWebTrojan.Webpick.9832
VIPRETrojan.Generic.34700691
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
GDataWin32.Application.Gemius.B (4x)
WebrootW32.Adware.Gen
GoogleDetected
VaristW32/ABRisk.WRDP-2332
ArcabitTrojan.Generic.D2117D93
MicrosoftPUA:Win32/Gemius
ALYacTrojan.Generic.34700691
MAXmalware (ai score=81)
VBA32Trojan.WebPick
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallTROJ_GEN.R002H09B224
RisingMalware.Heuristic!ET#98% (CLOUD)
MaxSecureTrojan.W32.gemius.1_344562
FortinetRiskware/Application
AVGWin32:PUP-gen [PUP]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (W)

How to remove PUA:Win32/Gemius?

PUA:Win32/Gemius removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment