PUA

About “PUA:Win32/PcSuperWeather” infection

Malware Removal

The PUA:Win32/PcSuperWeather is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/PcSuperWeather virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • CAPE detected the VMProtectStub malware family
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine PUA:Win32/PcSuperWeather?


File Info:

name: 0A8EAFBCD3ABAC344164.mlw
path: /opt/CAPEv2/storage/binaries/597281c55efcbfa3d110ae51a2b49376f7915aa1a8582022656782a688a290ea
crc32: F51DD1FF
md5: 0a8eafbcd3abac3441647f1c0e71ec53
sha1: 158934c7a99efeb72f2c174ca4fcfa3d3ae5c034
sha256: 597281c55efcbfa3d110ae51a2b49376f7915aa1a8582022656782a688a290ea
sha512: df9a7620d8dac4dd44132d7c72a88fe9551ad6957c69675381cd414ee9db62c41aa87ea93a5d70b2314778e47c9878f1bff152d34b2c7537de833fa710fd09c2
ssdeep: 98304:BHxYuAE3lETDFakzAwMmKLV0ijyoYC6vPMoiMxzqqpo4b:BHWjymDFRMaTTvPmYzo4b
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AA0611172E8CD623EBA1AA31E50165FE44D39C81C9F45C1BE8F8BF9876F0365983740A
sha3_384: 3bf3315fdfcc3a7c7e166828e529b2ad1e19225f99500de135e1901c48884eda501473e32f6f917d136bd922a942f59b
ep_bytes: e95feeffff451e13f93c1f2cfc6ce74b
timestamp: 2015-07-14 17:04:59

Version Info:

FileVersion: 2.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 2.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

PUA:Win32/PcSuperWeather also known as:

LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Fragtor.108629
ALYacGen:Variant.Fragtor.108629
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDownloader.Plocust.Win32.259942
SangforPUP.Win32.FlyStudio.V6ua
K7AntiVirusAdware ( 0053c8811 )
AlibabaDownloader:Win32/FlyStudio.6e168783
K7GWAdware ( 0053c8811 )
CrowdStrikewin/grayware_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.36196.JF1@aW0Llcfb
VirITTrojan.Win32.Generic.BSJQ
CyrenW32/S-d75b8d8e!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/FlyStudio.Injector.D potentially unwanted
APEXMalicious
ClamAVWin.Trojan.Agent-1346889
Kasperskynot-a-virus:Downloader.Win32.AdLoad.revv
BitDefenderGen:Variant.Fragtor.108629
NANO-AntivirusTrojan.Win32.dyjmcv.eaqein
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10bd87a3
EmsisoftGen:Variant.Fragtor.108629 (B)
VIPREGen:Variant.Fragtor.108629
TrendMicroTROJ_GEN.R03BC0PDM23
McAfee-GW-EditionPUP-XAC-EJ
Trapminesuspicious.low.ml.score
FireEyeGen:Variant.Fragtor.108629
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Fragtor.108629
JiangminTrojan.Generic.foso
GoogleDetected
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.TSGeneric
XcitiumTrojWare.Win32.Agent.ISVQ@5mbonp
ArcabitTrojan.Fragtor.D1A855
ZoneAlarmnot-a-virus:Downloader.Win32.AdLoad.revv
MicrosoftPUA:Win32/PcSuperWeather
CynetMalicious (score: 100)
AhnLab-V3PUP/Win.Generic.R519127
McAfeePUP-XAC-EJ
VBA32TScope.Malware-Cryptor.SB
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0PDM23
RisingPUF.PcSuperWeather!8.FAD6 (TFE:2:egEJod2l3NN)
YandexPUA.Downloader!l5Be6birHhc
Ikarusnot-a-virus:Downloader.FlyStudio
MaxSecureDropper.Dinwod.frindll
FortinetRiskware/FlyStudio_Packed
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.cd3aba
DeepInstinctMALICIOUS

How to remove PUA:Win32/PcSuperWeather?

PUA:Win32/PcSuperWeather removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment