PUA

About “PUA:Win32/SuspiciousProcStarter” infection

Malware Removal

The PUA:Win32/SuspiciousProcStarter is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/SuspiciousProcStarter virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine PUA:Win32/SuspiciousProcStarter?


File Info:

crc32: 693F1C68
md5: ad3880c8ced9fd43e0bfa4cc4d074f52
name: ela-salaty_.exe
sha1: 0b01ecca10dc2ff19c9ebb7d60181985a53e89e4
sha256: d88d8a0ace90e7830ef08729e2e7e449f91cfbf4842e9d612245ca8f9d3502ad
sha512: 394b849d37cf74dc93eb068a684d21522d66e24f6e2b03301cda715a73079f9a1caa1b0c9c1a96ce33f5f52423ea06f14b57d2d71403173e450afe81d9c15b25
ssdeep: 49152:Nh0Ag/GBrz0Z87Tq6mhMBtYpxlioLvLn2aPI1N37HNKNrRtMeL7:n0/OBroZ8i6mh2tYTlisvLFqN3Dc/LL7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Bakebihoma
FileVersion:
CompanyName:
Comments: This installation was built with Inno Setup.
ProductName: Takofut
ProductVersion: 3.1.8
FileDescription: Takofut Setup
Translation: 0x0000 0x04b0

PUA:Win32/SuspiciousProcStarter also known as:

MicroWorld-eScanApplication.DealAlpha.2.Gen
FireEyeGeneric.mg.ad3880c8ced9fd43
CAT-QuickHealTrojan.Puwaders
MalwarebytesAdware.InstallCore
VIPRETrojan.Win32.Generic!BT
BitDefenderApplication.DealAlpha.2.Gen
CyrenW32/Application.PXPZ-8911
SymantecTrojan.Gen.2
ClamAVWin.Malware.Installcore-6912929-0
GDataWin32.Application.InstallCore.LR@gen
Kasperskynot-a-virus:HEUR:AdWare.Win32.DealPly.gen
ViRobotAdware.Installcore.2141684
AegisLabAdware.Win32.DealPly.2!c
Endgamemalicious (high confidence)
SophosInnoMod (PUA)
ComodoApplicUnwnt@#srreir2qz8ik
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.vc
Trapminemalicious.high.ml.score
EmsisoftApplication.DealAlpha.2.Gen (B)
JiangminAdWare.DealPly.lqpa
WebrootW32.Adware.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftPUA:Win32/SuspiciousProcStarter
ArcabitApplication.DealAlpha.2.Gen
ZoneAlarmnot-a-virus:AdWare.Win32.DealPly.heur
Acronissuspicious
McAfeeArtemis!AD3880C8CED9
CylanceUnsafe
PandaPUP/InstallCore
ESET-NOD32Win32/InstallCore.Gen.B potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R01FH0CDQ20
RisingPacker.Win32.Obfuscator.n (CLASSIC)
SentinelOneDFI – Suspicious PE
MaxSecureTrojan.Malware.12132270.susgen
FortinetW32/InnoMod.AYH
AVGFileRepMetagen [Malware]
Qihoo-360HEUR/QVM42.3.715F.Malware.Gen

How to remove PUA:Win32/SuspiciousProcStarter?

PUA:Win32/SuspiciousProcStarter removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment