PUA

PUA:Win32/ShopHome removal guide

Malware Removal

The PUA:Win32/ShopHome is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/ShopHome virus can do?

  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine PUA:Win32/ShopHome?


File Info:

name: AF56D90FC30DA47AC88E.mlw
path: /opt/CAPEv2/storage/binaries/c2241d09b527cd99786017bd78d6aea128d778972d3c09234df39ab9f8c6145a
crc32: 8A3E9222
md5: af56d90fc30da47ac88e8cd8f7cfe904
sha1: 2e2faace2534de40e8f6ffb36632199fd9927832
sha256: c2241d09b527cd99786017bd78d6aea128d778972d3c09234df39ab9f8c6145a
sha512: d29c45306cb0a24745cf304ebc631bb8fb5349d16e0d7455f728f730a21186247c2479c36c8579ac526e57f28018e9c6ba3b090829da8dd41fcc3067d5e73aad
ssdeep: 24576:LmHzuCbiWbK/ikl9qAMRV9GXQQLwXWZEBdy:5Cb5KqI9qDV9IQQLTZE6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E815128936B08325CD4749B260703A79AFA9FF18706CD049D36F77CAEB729E4780E561
sha3_384: 5495a65de586ecb1ae5331e11875be05c733ada299210c0625c545b16d6cd8b613ee73a8e0f9a0b9978f4c9b0eeb4026
ep_bytes: 81ec8401000053555633db57895c241c
timestamp: 2012-02-24 19:21:56

Version Info:

0: [No Data]

PUA:Win32/ShopHome also known as:

BkavW32.AIDetect.malware1
LionicRiskware.Win32.Generic.1!c
DrWebAdware.Shopper.1825
MicroWorld-eScanAdware.Generic.3009254
FireEyeGeneric.mg.af56d90fc30da47a
McAfeeArtemis!AF56D90FC30D
CylanceUnsafe
ZillyaAdware.ShopAtHome.Win32.15
K7AntiVirusRiskware ( 0040eff71 )
AlibabaAdWare:Win32/ShopAtHome.496ee399
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.fc30da
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/ShopAtHome.A potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0WH221
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-1636761
Kasperskynot-a-virus:UDS:AdWare.Win32.ShopAtHome.h
BitDefenderAdware.Generic.3009254
NANO-AntivirusRiskware.Win32.ShopAtHome.edxvtd
AvastWin32:Adware-gen [Adw]
RisingTrojan.Generic@ML.99 (RDMK:XHTXmBPFx0+jhQCQ+tuqGA)
Ad-AwareAdware.Generic.3009254
EmsisoftAdware.Generic.3009254 (B)
TrendMicroTROJ_GEN.R002C0WH221
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SophosGeneric Reputation PUA (PUA)
GDataWin32.Adware.ShopAtHome.C (6x)
Antiy-AVLTrojan/Generic.ASMalwS.2042858
ArcabitAdware.Generic.D2DEAE6
ViRobotAdware.Shopathome.904178
MicrosoftPUA:Win32/ShopHome
VBA32Adware.Shopper
ALYacAdware.Generic.3009254
MalwarebytesMalware.AI.4262587013
APEXMalicious
TencentTrojan.Win32.BitCoinMiner.la
SentinelOneStatic AI – Suspicious PE
FortinetAdware/ShopAtHomeSelect
AVGWin32:Adware-gen [Adw]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove PUA:Win32/ShopHome?

PUA:Win32/ShopHome removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment