PUA

About “Generic PUA CI (PUA)” infection

Malware Removal

The Generic PUA CI (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA CI (PUA) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs

How to determine Generic PUA CI (PUA)?


File Info:

crc32: 47ABC09A
md5: c03a39c9f9320fda5e880f83e8054a12
name: igra_v_duraka_na_dengi.exe
sha1: 280bb2f7801a0fdd84ec1111f92ccfab8511bafb
sha256: 782eb33fc225c3927969152fd27180805f8b9ff4f2d2ad63a4c61710ca114fab
sha512: 2696ea73a5580566a58f6bea26d5a47e34d0b66940f82a66c8287a9f2c3c2e4216c3528a23f3e701d168dd6fe7fc0cf523f0738d4db7e9f77f5dd902af95f2c2
ssdeep: 49152:AcsQ6Q/U6cAOpmhZ6Df1tEx//0z/Cpc8gERTUMP:A1QT86h4mr6Dd61/ppDgERPP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName: Offerbox
Comments: This installation was built with Inno Setup.
ProductName: igra_v_duraka_na_dengi
ProductVersion: 0.0.0.1
FileDescription: igra_v_duraka_na_dengi Setup
OriginalFileName:
Translation: 0x0000 0x04b0

Generic PUA CI (PUA) also known as:

K7AntiVirusAdware ( 0055782a1 )
K7GWAdware ( 0055782a1 )
APEXMalicious
AvastWin32:PUP-gen [PUP]
Kasperskynot-a-virus:HEUR:Downloader.Win32.OfferInstall.gen
NANO-AntivirusTrojan.Win32.Magala.flpthi
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazq+8NdHb2UmSiY5khrSnirO)
SophosGeneric PUA CI (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
EmsisoftApplication.AdOffer (A)
CyrenW32/S-70232f14!Eldorado
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.OfferInstall.gen
MicrosoftTrojan:Win32/Wacatac.C!ml
AhnLab-V3Malware/Win32.RL_Generic.R325068
Acronissuspicious
McAfeeArtemis!C03A39C9F932
MalwarebytesPUP.Optional.BundleInstaller
ESET-NOD32Win32/Appster.D potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R01FH05D320
IkarusAdWare.InnoBundle
WebrootW32.Adware.Gen
AVGWin32:PUP-gen [PUP]

How to remove Generic PUA CI (PUA)?

Generic PUA CI (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment