PUA

How to remove “PUA:Win32/Sien”?

Malware Removal

The PUA:Win32/Sien is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/Sien virus can do?

  • Attempts to connect to a dead IP:Port (4 unique times)
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Anomalous binary characteristics

Related domains:

geoloc.1stbrowser.com
data.bd-pl.com
setup2.1stbrowser.com
nist.time.gov

How to determine PUA:Win32/Sien?


File Info:

crc32: DB2F4D5F
md5: 45a7edf7c99c84ec3a9939ebc7361c32
name: 45A7EDF7C99C84EC3A9939EBC7361C32.mlw
sha1: c41d59087e9425d0362b41268eb903e8e4921911
sha256: 42161047834607e84a3f13760defc17d705b33177bf0a061d87ed46fae7b5f88
sha512: 07b154ae1d40a2fd19b02be5f8878a292ac972fa40f3f229270fe45af493699520a7372588c28f164b30e1007c087fbca9836e2eb353df431637f8da2c302cef
ssdeep: 49152:L/88G8UiT24uGg2Brd/W7IL2RLpGDgzTvrjzAjnMKo:LlG8Z24hg2Brd3S1pGDgzTLb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2016
InternalName: Installer.exe
FileVersion: 4.42.1.1
CompanyName: S
ProductName: Installer
ProductVersion: 4.42.1.1
FileDescription: Installer
OriginalFilename: Installer.exe
Translation: 0x0409 0x04b0

PUA:Win32/Sien also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.45a7edf7c99c84ec
McAfeeArtemis!45A7EDF7C99C
CylanceUnsafe
ZillyaAdware.CognosAdsCRTD.Win32.7992
SangforMalware
K7AntiVirusAdware ( 004dc6491 )
K7GWAdware ( 004dc6491 )
InvinceaGeneric PUA ME (PUA)
CyrenW32/Strictor.BK.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Trojan.Autoit-9790147-0
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
EmsisoftApplication.AdLoad (A)
DrWebAdware.Iminent.132
VIPRE1stBrowser (fs)
McAfee-GW-EditionArtemis!Trojan
SophosGeneric PUA ME (PUA)
SentinelOneStatic AI – Suspicious PE
JiangminAdWare.Generic.saak
AviraADWARE/CognosAds.Gen
eGambitPE.Heur.InvalidSig
Antiy-AVLGrayWare[AdWare]/Win32.CognosAds.gg
GridinsoftAdware.Iminent.vl!c
MicrosoftPUA:Win32/Sien
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Generic
CynetMalicious (score: 90)
AhnLab-V3PUP/Win32.CognosAds.R214870
VBA32BScope.Adware.Shoppers
MalwarebytesPUP.Optional.1stBrowser
ESET-NOD32a variant of Win32/Adware.CognosAds.G
TrendMicro-HouseCallTROJ_GEN.R06CH0CKI20
RisingTrojan.Generic@ML.90 (RDML:tq0tJmXOGXscrx2dxHF5cg)
IkarusPUA.CognosAds
AVGWin32:Adware-DLV [PUP]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove PUA:Win32/Sien?

PUA:Win32/Sien removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment