PUA

PUA:Win32/Privitize removal

Malware Removal

The PUA:Win32/Privitize is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/Privitize virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine PUA:Win32/Privitize?


File Info:

name: C72AF49FE4F345A58D58.mlw
path: /opt/CAPEv2/storage/binaries/c547984ae339c734253b4d4b3392fa7d01750b9cfd2b6676f072465a713caede
crc32: 5E2C6CB0
md5: c72af49fe4f345a58d5839bdf0410e72
sha1: 04cb1f6117b5268d0ff42053338b5d1fbb326781
sha256: c547984ae339c734253b4d4b3392fa7d01750b9cfd2b6676f072465a713caede
sha512: 46e9929d5bdce2641efa8beb88516d5e747cd36921f9d95480f3aa0ba69435ff9d60efad757b2d88a673b9d7b47917c5c4975836eae9abdd3e3f49aa63da61b4
ssdeep: 3072:KFqmotgegZwrDNKzg3IKuKfxWKHC3zGSrKOn5drM0emHg9T5N:oqmzZZwvWQIKhnHvSH5Lkn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T112D3080033F3AA31E9A7933A06EB7BED273DFB258BA169C753403A16C7709D45531A52
sha3_384: 6f7ba4edd782f7f93bcb5db772d37ed05ce012956e5c37158a0f94a9ffbfd5a12ff9725a1b8653600311eae6a0669687
ep_bytes: e8d3300000e97ffeffff558bec518d45
timestamp: 2015-08-28 11:51:43

Version Info:

CompanyName: InternetSecurity Inc
FileDescription: Amazing security tool
FileVersion: 1.0.0.8
InternalName: WIT
LegalCopyright: Copyright 2015 InternetSecurity Inc, All rights reserved.
OriginalFilename: WIT.exe
ProductName: WebInstaller
ProductVersion: 1.0.0.8
Translation: 0x0409 0x04b0

PUA:Win32/Privitize also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Zusy.452930
FireEyeGeneric.mg.c72af49fe4f345a5
ALYacGen:Variant.Zusy.452930
MalwarebytesMalware.AI.256852099
VIPREGen:Variant.Zusy.452930
ArcabitTrojan.Zusy.D6E942
VirITTrojan.Win32.Startpage.XYT
CyrenW32/Trojan.WLIO-3049
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/StartPage.AMR
APEXMalicious
BitDefenderGen:Variant.Zusy.452930
NANO-AntivirusTrojan.Win32.StartPage.dwqznn
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Startpage.ka
TACHYONTrojan/W32.Agent.137728.TZ
F-SecureHeuristic.HEUR/AGEN.1306257
McAfee-GW-EditionGenericRXVY-CJ!C72AF49FE4F3
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Zusy.452930 (B)
GoogleDetected
AviraHEUR/AGEN.1306257
Antiy-AVLTrojan/Win32.BTSGeneric
MicrosoftPUA:Win32/Privitize
GDataWin32.Trojan.PSE.J54LKO
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.C5395059
MAXmalware (ai score=80)
Cylanceunsafe
RisingTrojan.StartPage!8.B (TFE:5:GYLIW9rJg3L)
YandexTrojan.GenAsa!O1dXp/Jssbo
IkarusPUA.Techsnab
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Wacatac.B!tr
BitDefenderThetaGen:NN.ZexaF.36196.iy0@amaix0gi
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove PUA:Win32/Privitize?

PUA:Win32/Privitize removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment