PUA

Should I remove “PUA:Win32/Sunwork”?

Malware Removal

The PUA:Win32/Sunwork is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/Sunwork virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine PUA:Win32/Sunwork?


File Info:

name: DAF065F9BF016CB89A84.mlw
path: /opt/CAPEv2/storage/binaries/e46f9a848b1d54e7dbd7846c5b24dd2abafa66f873d4783cad36eaf8416ef35b
crc32: 756F7922
md5: daf065f9bf016cb89a84820d6503f664
sha1: 885fb8858b2203fe88746ba28c596a6fece4a80d
sha256: e46f9a848b1d54e7dbd7846c5b24dd2abafa66f873d4783cad36eaf8416ef35b
sha512: d0538d8d8226c1ce0231aa0c2e2bc7ce112cdb500b96ee72800a2dc2615a1a2aaee4bf2b3bffa3736c8da94aafb837be57ab44e57580cc3ad996b72cfb0b1f25
ssdeep: 6144:Z/na4k4gTuW4AICXsWfnKPTQGS+4aVm2b6oRKVo/ZPzSMwp5HhsalprDkLHisO29:Rna94gT6AjnKEGF4O2DnM2xk/O29
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C1841222D5E2843AE0619DF06E2AC5189F333D772E39242A33CC8D5D5F36AD1D60A767
sha3_384: 6bdf8bec8d815bd7f5a9b2abb296be36323a172815c023f67a1120718221372fbfa4ce2d6b4c4ab7d262155c38eccdd5
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: SunWork Media
FileDescription: FormaliteFacile Setup
FileVersion:
LegalCopyright:
ProductName: FormaliteFacile
ProductVersion: 1
Translation: 0x0000 0x04b0

PUA:Win32/Sunwork also known as:

BkavW32.Common.5EFECDD4
MicroWorld-eScanGen:Trojan.StartPage.kuW@aKUyLCei
FireEyeGen:Trojan.StartPage.kuW@aKUyLCei
SkyhighArtemis!Trojan
McAfeeArtemis!DAF065F9BF01
MalwarebytesStartpage.Riskware.Hijacker.DDS
ZillyaTool.StartPage.Win32.463
K7AntiVirusRiskware ( 00537bf41 )
AlibabaTrojan:Win32/StartPage.af4c2fc0
K7GWRiskware ( 00537bf41 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Startpage
ESET-NOD32Win32/RiskWare.StartPage.N
TrendMicro-HouseCallTROJ_GEN.R002C0OB124
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Trojan.StartPage.kuW@aKUyLCei
NANO-AntivirusTrojan.Win32.StartPage.fffcuy
AvastWin32:Malware-gen
EmsisoftGen:Trojan.StartPage.kuW@aKUyLCei (B)
DrWebTrojan.StartPage.51018
VIPREGen:Trojan.StartPage.kuW@aKUyLCei
TrendMicroTROJ_GEN.R002C0OB124
SophosMal/Generic-S
MAXmalware (ai score=82)
Antiy-AVLRiskWare/Win32.StartPage
KingsoftWin32.Infected.AutoInfector.a
MicrosoftPUA:Win32/Sunwork
XcitiumMalware@#8eik87kfl6c6
ArcabitTrojan.StartPage.ED1E30
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Trojan.StartPage.kuW@aKUyLCei
BitDefenderThetaAI:Packer.35C4B9AC1F
ALYacGen:Trojan.StartPage.kuW@aKUyLCei
VBA32Trojan.StartPage
Cylanceunsafe
RisingPUA.Sunwork!8.F91B (CLOUD)
YandexTrojan.GenAsa!1pWCtcR5WHA
MaxSecureTrojan.Malware.7980.susgen
FortinetRiskware/Generic_PUA_GH
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove PUA:Win32/Sunwork?

PUA:Win32/Sunwork removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment