PUA

PUA:Win32/ShopperPro removal instruction

Malware Removal

The PUA:Win32/ShopperPro is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/ShopperPro virus can do?

  • Uses Windows utilities for basic functionality
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Deletes executed files from disk
  • Attempts to disable UAC
  • Attempts to disable Windows Defender
  • Uses suspicious command line tools or Windows utilities

How to determine PUA:Win32/ShopperPro?


File Info:

name: 87529C35F2080498D076.mlw
path: /opt/CAPEv2/storage/binaries/7a3e1131663cd810c571934d3da66dc4a47da361358efd47730e103a8fbf3572
crc32: D93789BB
md5: 87529c35f2080498d076fec0adf53005
sha1: 8a11659b5ff7ab2b731ede3ea719084e7f290554
sha256: 7a3e1131663cd810c571934d3da66dc4a47da361358efd47730e103a8fbf3572
sha512: 7c65132941e37266e88d496440d22cd6a8b255f157b596854287fc61fab448060fd246b93716e6ddd2a759de53ae79363eb04f95a466568376dfa6993baefa4f
ssdeep: 49152:t4SH/7T5cvP41sBRHf3b/hWdg8zqiAvZpVBtT7jcxYXrPCwagHm8hNK+Zzd4H+O:tb/KYs3Hf3b/Qdgthx7PXQxQCEPKwC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A8E50121B691C077E4A36136CDAA8775A679B8315B7092CF77900BB90F332E25E39347
sha3_384: a01c9333b1ddf4a68dd0188bbaa91974d4cd954d6cabd1024ec002e96bfe761d5aa6617d9536b48c017e01209a0ee2a0
ep_bytes: e897a70000e978feffff8bff558bec83
timestamp: 2021-07-08 03:34:12

Version Info:

Comments: almany System.
CompanyName: almany Company.
FileDescription: almany Program.
FileVersion: 1, 0, 0, 1
InternalName: almany.exe
LegalCopyright: almany Company.Copyright (C) 2017.
OriginalFilename: almany.exe
ProductName: almany Program.
ProductVersion: 1, 0, 0, 1
Translation: 0x0412 0x04b0

PUA:Win32/ShopperPro also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.JackServn.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Downloader.184
FireEyeGeneric.mg.87529c35f2080498
SkyhighBehavesLike.Win32.Generic.wc
MalwarebytesJackServn.Trojan.Downloader.DDS
VIPREGen:Variant.Downloader.184
SangforVirus.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/SchoolBoy.96ee74e6
K7GWTrojan ( 0057265a1 )
K7AntiVirusTrojan ( 0057265a1 )
ArcabitTrojan.Downloader.184
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/JackServn.W
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.SchoolBoy.gen
BitDefenderGen:Variant.Downloader.184
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.11b84bf2
SophosMal/Generic-S
F-SecureTrojan.TR/JackServn.nsanv
DrWebTrojan.Siggen14.30256
ZillyaTrojan.JackServn.Win32.250
TrendMicroTROJ_GEN.R002C0PK423
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Downloader.184 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Schoolboy.nj
AviraTR/Razy.AE
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.SchoolBoy
KingsoftWin32.Trojan.SchoolBoy.gen
XcitiumApplication.Win32.DomaIQ.D@5607rc
MicrosoftPUA:Win32/ShopperPro
ZoneAlarmHEUR:Trojan.Win32.SchoolBoy.gen
GDataGen:Variant.Downloader.184
AhnLab-V3Trojan/Win.Generic.R457504
McAfeeGenericRXPE-YQ!87529C35F208
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0PK423
RisingTrojan.JackServn!8.2B9 (TFE:5:2kF5gKAXytB)
YandexTrojan.SchoolBoy!aJZ/mBoMHpA
IkarusTrojan.Win32.Jackservn
MaxSecureTrojan.Malware.10640424.susgen
FortinetW32/JackServn.W!tr
BitDefenderThetaGen:NN.ZexaF.36792.muW@au00Wnm
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.b5ff7a
DeepInstinctMALICIOUS

How to remove PUA:Win32/ShopperPro?

PUA:Win32/ShopperPro removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment