PUA

Should I remove “PUA:Win32/PhoneRooter”?

Malware Removal

The PUA:Win32/PhoneRooter is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/PhoneRooter virus can do?

  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine PUA:Win32/PhoneRooter?


File Info:

crc32: E54CC470
md5: 62d39dfce8dea662a4fc91a30a5ff6bc
name: tmpgm2krbs8
sha1: 314841738b7f50c6b4603d55f67ded1c8650dbf9
sha256: 97adddce7151d5cbd6e299be8a74a8e50679aab9f5d4061f8314bd47f7ee72fa
sha512: b11f7746a9174af3f53810d7bd6f3cecdf1380559ad513d43b3c03b95f2e3a9fb18d817edd1ddba3e6c791c9b0460bcbdfc3109106e9637c122b171c15efcdfe
ssdeep: 786432:T5d/wxcSI9s5c0PYi9W4f72TdA9slRIZjbyNIjqRiisrXWfkDBeO:T5d/qcSb5c0gqFyZA9IiZjvq8isDWcD/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

PUA:Win32/PhoneRooter also known as:

MicroWorld-eScanGen:Variant.Mikey.109643
Qihoo-360Generic/Trojan.619
ALYacGen:Variant.Mikey.109643
AegisLabTrojan.Win32.Mikey.4!c
BitDefenderGen:Variant.Mikey.109643
CyrenAndroidOS/Lotoor.C.gen!Eldorado
SymantecSMG.Heur!gen
APEXMalicious
GDataGen:Variant.Mikey.109643
Ad-AwareGen:Variant.Mikey.109643
F-SecureHeuristic.HEUR/AGEN.1044574
ZillyaDropper.Agent.Win32.354749
McAfee-GW-EditionArtemis
FireEyeGeneric.mg.62d39dfce8dea662
SophosGeneric PUA DB (PUA)
IkarusTrojan.Win32.Agent
AviraHEUR/AGEN.1044574
Endgamemalicious (high confidence)
ArcabitTrojan.Mikey.D1AC4B
MicrosoftPUA:Win32/PhoneRooter
MAXmalware (ai score=84)

How to remove PUA:Win32/PhoneRooter?

PUA:Win32/PhoneRooter removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment