PUA

PUA:Win32/Papras removal instruction

Malware Removal

The PUA:Win32/Papras is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/Papras virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Creates a slightly modified copy of itself

How to determine PUA:Win32/Papras?


File Info:

crc32: DE6CD510
md5: 8ea913cde61956af8e39bb2f6b3ee261
name: 8EA913CDE61956AF8E39BB2F6B3EE261.mlw
sha1: fd6cc1bd83a6a1270ef1c42cb677892b1f79d2ea
sha256: c32fe9dbac090d5efab2f8016026e0e34ce38151d47514d92fa34c89395b29f1
sha512: 173c589e3eb7db195e90c24bab56ae1c8773f3343a3c5e0fc82ef893c5c03669ab5af1aabae6ebf38bfb116daf11a06f2e7d31f7efc507e12f3ba3b4461c64ac
ssdeep: 6144:/YFz75Q00buEGpdWXWU51fu0sNfeuZMMdijAWc1ef2heNnYQ4Kwn:A575Q0pdWBefeuZMMdijAuuheNQn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xfffd 2015 Trimble Navigation Limited
InternalName: SketchUp
FileVersion: 16.0.1.2
CompanyName: Trimble Navigation Limited
ProductName: SketchUp Pro 2016-32-bit
ProductVersion: 16.0.1.2
FileDescription: SketchUp Pro 2016-32-bit
OriginalFilename: SketchUp.exe
Translation: 0x0409 0x04b0

PUA:Win32/Papras also known as:

K7AntiVirusTrojan ( 00585dd51 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Papras.1786
McAfeeGeneric.anf
CylanceUnsafe
ZillyaTrojan.AgentCRTD.Win32.4918
SangforInfostealer.Win32.Agent.lshj
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/Kryptik.c5b31556
K7GWTrojan ( 00585dd51 )
Cybereasonmalicious.de6195
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.FHVN
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win32.Agent.lshj
BitDefenderGen:Variant.Johnnie.337871
NANO-AntivirusTrojan.Win32.Agent.engzdi
ViRobotTrojan.Win32.Z.Crypt.445272
MicroWorld-eScanGen:Variant.Johnnie.337871
TencentWin32.Trojan-qqpass.Qqrob.Eerp
Ad-AwareGen:Variant.Johnnie.337871
SophosMal/Generic-R + Troj/Gozi-EX
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0OJ121
McAfee-GW-EditionGeneric.anf
FireEyeGeneric.mg.8ea913cde61956af
EmsisoftGen:Variant.Johnnie.337871 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Agent.alzh
WebrootW32.Trojan.Gen
MicrosoftPUA:Win32/Papras
GDataGen:Variant.Johnnie.337871
VBA32BScope.TrojanSpy.Zbot
MAXmalware (ai score=100)
MalwarebytesMalware.AI.2657446276
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0OJ121
RisingTrojan.Generic@ML.87 (RDMK:82sGzLklQT33vVcON+8GIg)
IkarusTrojan-Spy.Remcos
FortinetW32/Kryptik.FQUM!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove PUA:Win32/Papras?

PUA:Win32/Papras removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment