PUA

PUA:Win32/Hypnamer.A!ml removal instruction

Malware Removal

The PUA:Win32/Hypnamer.A!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/Hypnamer.A!ml virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine PUA:Win32/Hypnamer.A!ml?


File Info:

crc32: 6FE05673
md5: 1b2c5bffa435cb37e2932a0caf65055e
name: 1B2C5BFFA435CB37E2932A0CAF65055E.mlw
sha1: fd9daf6c4b8a49cec1305a951c7dfd74e054e4ee
sha256: ec1803040bcb7692c691f09aee999add7e323f6cec45521762b4fc6b21ad1593
sha512: da877b1cb3ee96bfc61c7b5ae8da7ec610384b66f653d364c2068c3b12b768cff19bc9f0d88a84804e04ce34453b8b99ac0eee5694b12d18c544583f40431bc4
ssdeep: 98304:PWCj4CIbPoSxZ2uWHxhACdqsUYqexq5dOU3RQD8sq:PWC0Ca/YVbAMj9xq5485
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x4e0ax6d77x5e7fx4e50x7f51x7edcx79d1x6280x6709x9650x516cx53f8. Copyright 2010-2013
InternalName: Kuaizip Install
FileVersion: 2.9.2.1
Comments: www.kpzip.com
ProductName: x5febx538bx8f6fx4ef6x7a0bx5e8f
ProductVersion: 2.9.2.1
FileDescription: x5febx538bx5b89x88c5x5305x7a0bx5e8f
OriginalFilename: KuaiZip Setup
Translation: 0x0804 0x04b0

PUA:Win32/Hypnamer.A!ml also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Babar.23157
FireEyeGeneric.mg.1b2c5bffa435cb37
McAfeeAdware-KZip
SangforMalware
K7AntiVirusUnwanted-Program ( 00560ccc1 )
BitDefenderGen:Variant.Babar.23157
K7GWUnwanted-Program ( 00560ccc1 )
ClamAVWin.Packed.Emotet-9790742-0
Kasperskynot-a-virus:HEUR:AdWare.Win32.KuziTui.gen
Ad-AwareGen:Variant.Babar.23157
DrWebProgram.Kuaizip.3
InvinceaGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.wc
EmsisoftGen:Variant.Babar.23157 (B)
SentinelOneStatic AI – Malicious PE
MicrosoftPUA:Win32/Hypnamer.A!ml
GridinsoftAdware.Win32.Kuaiba.vl!i
ArcabitTrojan.Babar.D5A75
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.KuziTui.gen
GDataGen:Variant.Babar.23157
CynetMalicious (score: 100)
Acronissuspicious
MAXmalware (ai score=88)
VBA32BScope.Downloader.KuziTui
MalwarebytesPUP.Optional.Kuaizip
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/KuaiZip.B potentially unwanted
RisingAdware.AdPop!1.C7AA (CLASSIC)
YandexTrojan.GenAsa!rvjWbj1KbkY
eGambitUnsafe.AI_Score_99%
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureVirus.Downloader.Win32.KuziTui.gen.a

How to remove PUA:Win32/Hypnamer.A!ml?

PUA:Win32/Hypnamer.A!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment