Trojan

About “Trojan.Purityad.D” infection

Malware Removal

The Trojan.Purityad.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Purityad.D virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Purityad.D?


File Info:

name: 8ABEDA7307AE8E9CBC53.mlw
path: /opt/CAPEv2/storage/binaries/9a9dd79cd92f1401a30c9e3882a36be4430753500ec87cf838c69924e2a281f5
crc32: 7B068DA3
md5: 8abeda7307ae8e9cbc533d6f708c3061
sha1: cebc1e6f9cdbbcd2cf82e240e7a5960ef6a86af9
sha256: 9a9dd79cd92f1401a30c9e3882a36be4430753500ec87cf838c69924e2a281f5
sha512: 2f2344557c876e9184289489ee9223980d3c65d61835de3f3515b4f91a10562d53bb48a23a01842bcbd11b18e36879087bef4d3c6fef7a49af5c0eb661bedb46
ssdeep: 3072:L73tmtpMBZD0+aLhkXb45i9SXMbLu/bKiYe7wuUZNTbt73:1mJ3L0aXmLuDKvXZN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B41429FEB9D254E2E4878AB0237F4275403A6CB207415AC6C70FAD6724B990971DBBC7
sha3_384: 9f12f9b5b3f7b72af4368789531bec3efe17a78f4a65c00fd2e0e9174006810c53675e617c630258581b70bea6ae27ad
ep_bytes: 558bec6aff68b04a410068a898400064
timestamp: 2004-07-16 19:47:20

Version Info:

Comments:
CompanyName:
FileDescription: MFC Application
FileVersion: 1, 0, 0, 1
InternalName:
LegalCopyright: Copyright (C) 2002
LegalTrademarks:
OriginalFilename: VIRTUESCOPE
PrivateBuild:
ProductName: VIRTUESCOPE Application
ProductVersion: 1, 0, 0, 1
SpecialBuild:
Translation: 0x0409 0x04b0

Trojan.Purityad.D also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.PurityScan.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Purityad.D
SkyhighAdware-ClickSpring.e
McAfeeAdware-ClickSpring.e
MalwarebytesPurityScan.Trojan.Downloader.DDS
VIPRETrojan.Purityad.D
SangforSuspicious.Win32.Save.ins
K7AntiVirusAdware ( 004ee78f1 )
BitDefenderTrojan.Purityad.D
K7GWAdware ( 004ee78f1 )
Cybereasonmalicious.f9cdbb
BitDefenderThetaGen:NN.ZexaF.36792.mq2@a4Jq0bfi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.PurityScan.AA
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Scapur-11
KasperskyHEUR:Trojan-Downloader.Win32.PurityScan.gen
AlibabaTrojanDownloader:Win32/PurityScan.62360678
NANO-AntivirusTrojan.Win32.Agent.elhooy
RisingRansom.PornoAsset!8.6AA (TFE:5:xaLOMST6yEQ)
TACHYONTrojan-Downloader/W32.PurityScan.204800.D
SophosGeneric Reputation PUA (PUA)
F-SecureTrojan.TR/Redcap.pmwmk
DrWebTrojan.PurityAd
ZillyaAdware.PurityScan.Win32.685
TrendMicroTROJ_GEN.R002C0PH423
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.8abeda7307ae8e9c
EmsisoftTrojan.Purityad.D (B)
IkarusTrojan-Downloader.Win32.PurityScan
JiangminTrojanDropper.PurityScan.ab
VaristW32/PurityScan.D.gen!Eldorado
AviraTR/Redcap.pmwmk
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Wacatac.A!ml
XcitiumTrojWare.Win32.TrojanDropper.PurityScan.DA@3aj5s4
ArcabitTrojan.Purityad.D
ZoneAlarmHEUR:Trojan-Downloader.Win32.PurityScan.gen
GDataTrojan.Purityad.D
GoogleDetected
AhnLab-V3Trojan/Win.HDC.R595282
VBA32TrojanDropper.PurityScan
ALYacTrojan.Purityad.D
MAXmalware (ai score=80)
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0PH423
TencentMalware.Win32.Gencirc.11b51888
YandexTrojan.PornoAsset!EE6Ac+UyonQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/PurityScan
AVGWin32:PurityScan-AB [Trj]
AvastWin32:PurityScan-AB [Trj]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan.Purityad.D?

Trojan.Purityad.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment