PUA

About “ZProtected (PUA)” infection

Malware Removal

The ZProtected (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ZProtected (PUA) virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine ZProtected (PUA)?


File Info:

name: E3ED94AF3718E6723E97.mlw
path: /opt/CAPEv2/storage/binaries/054e51b45535dd5ecebd5f801d0fb2fa614b458f72edf6b6f66cc4c3ccf003b8
crc32: 31BB38FE
md5: e3ed94af3718e6723e9771d5155e4ee2
sha1: f1337db2c20ecc76e4cdacd66e83f422036b3e09
sha256: 054e51b45535dd5ecebd5f801d0fb2fa614b458f72edf6b6f66cc4c3ccf003b8
sha512: f98e54756805d313c294cc3198209d020e8e0ecf0752b158b9c95242fc508f312b5cc55a24cbb2905786e3d0ac8377cad57a9fd490049848466f37e3c319b2e4
ssdeep: 1536:BaMeKYsEtkKDUmUla3agCJWF7K/hEsmv5yBW/qTUrYAyWb14TKiXjilOux/:BteY4nDbfagCqKZk5yY/QkeWiTKlXx/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T169830221CA9D2B83DA287D7588570A5B4C4DA6926FCD330C7CFE09248296B8C7BD17C7
sha3_384: 6a8224debed7fc43a999f315d5f759f22d354b32d06a70c9c06ca8a7eeef8fab108cd6410a71ad4f6e0839f00acdfabc
ep_bytes: e80100000038870c248d89d8fdffff87
timestamp: 2010-07-13 14:43:57

Version Info:

0: [No Data]

ZProtected (PUA) also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
ClamAVWin.Malware.Generic-9856856-0
FireEyeGeneric.mg.e3ed94af3718e672
ZillyaTrojan.Scar.Win32.67867
SangforSuspicious.Win32.Save.a
AlibabaBackdoor:Win32/EncPk.68f6990e
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
tehtrisGeneric.Malware
APEXMalicious
CynetMalicious (score: 100)
SophosZProtected (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.mc
Trapminemalicious.high.ml.score
SentinelOneStatic AI – Malicious PE
WebrootTrojan:Win32/Servstart.A
MicrosoftTrojan:Win32/Wacatac.B!ml
ViRobotTrojan.Win32.A.Scar.121019.F
GoogleDetected
AhnLab-V3Trojan/Win32.Scar.R8195
Acronissuspicious
McAfeeBackDoor-EXZ
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallTROJ_GEN.R002H06HC23
IkarusBackdoor.Win32.Zegost
FortinetPossibleThreat.RF
DeepInstinctMALICIOUS

How to remove ZProtected (PUA)?

ZProtected (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment