PUA

What is “Generic PUA CL (PUA)”?

Malware Removal

The Generic PUA CL (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA CL (PUA) virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.

Related domains:

downloader.downerapi.com

How to determine Generic PUA CL (PUA)?


File Info:

crc32: 7FF934B9
md5: e7e379f6c8cae723f220595dd6c5053f
name: 802.11n_____
sha1: 2b2be2110f0a0d417e3df6082225bb0e510ae7e0
sha256: 9c5784ca4eb828f92a56577d693c60e0d503607384c10cf0fda3d2b4da6afee8
sha512: 5a0635a681b0a79e069fdb7e92dd4871b8f312e4a0e9753cd7b85008cf7b285a81ac0b7982704fb9dd9448692295c9ab2abb6f71ac3f6c84b6923fa1b14c880f
ssdeep: 24576://Kjz7UAwOJV3yjauXWWonKaeDcqcdeZe6bz4sBN3d/://KP7fwOJV3yjavnKae/cdie6I2N3d/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018
InternalName: FastDownloader.exe
FileVersion: 3.2.0.8
CompanyName: -
ProductName: x8f6fx4ef6x4e0bx8f7dx5668
ProductVersion: 3.2.0.8
FileDescription: x8f6fx4ef6x4e0bx8f7dx5668
OriginalFilename: FastDownloader.exe
Translation: 0x0804 0x04b0

Generic PUA CL (PUA) also known as:

MicroWorld-eScanGen:Variant.Adware.Downloader.211
FireEyeGeneric.mg.e7e379f6c8cae723
ALYacGen:Variant.Adware.Downloader.211
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 00544e421 )
BitDefenderGen:Variant.Adware.Downloader.211
K7GWRiskware ( 00544e421 )
Invinceaheuristic
CyrenW32/Adware.OOYD-7795
SymantecTrojan.Gen.2
APEXMalicious
GDataGen:Variant.Adware.Downloader.211
AlibabaRiskWare:Win32/Downer.bd86ae47
ViRobotAdware.Downer.1135456.A
TencentMalware.Win32.Gencirc.10b90e3a
Ad-AwareGen:Variant.Adware.Downloader.211
SophosGeneric PUA CL (PUA)
ComodoApplicUnwnt@#37mo6e07gyx5l
ZillyaTool.Downer.Win32.54
EmsisoftApplication.Downloader (A)
IkarusPUA.RiskWare.Downer
Antiy-AVLRiskWare/Win32.Downer
Endgamemalicious (high confidence)
ArcabitTrojan.Adware.Downloader.211
MicrosoftPUA:Win32/Downer
AhnLab-V3PUP/Win32.Generic.C3478818
McAfeeArtemis!E7E379F6C8CA
MAXmalware (ai score=99)
MalwarebytesPUP.Optional.FastDownloader
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/RiskWare.Downer.A
TrendMicro-HouseCallTROJ_GEN.R049H0CCN20
RisingAdware.Downloader!1.BD64 (CLOUD)
eGambitUnsafe.AI_Score_99%
FortinetRiskware/Downer
AVGFileRepMalware [PUP]
Paloaltogeneric.ml

How to remove Generic PUA CL (PUA)?

Generic PUA CL (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment