PUA

Generic PUA CO (PUA) (file analysis)

Malware Removal

The Generic PUA CO (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA CO (PUA) virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs

How to determine Generic PUA CO (PUA)?


File Info:

crc32: 03C47D87
md5: a44be911d514055b199831e3569a45f4
name: ____________.exe
sha1: 2ec8a0b4dbf88edce9d04b6be86e02625302c527
sha256: 4ef0613273e1f8ee4ebdd6c21770c8f3c39797d0e55da3c602b1c930efb3d860
sha512: 7763c977ebd72180295dde939213d8ac013fc0e948a609717c4205949102234bc62e750810c5cd9ddea0f3ebfd98c7b4cac94678b65583d061f1715d2c325ed7
ssdeep: 12288:8/91KbXg9qPx5/M80QNG6OK4cw3wK41PMxoE:8HKbw9Cxlt0eG6OK4cw3wKCPIF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x8d75x6587x9f99 x7248x6743x6240x6709
FileVersion: 1.0.0.0
CompanyName: x8d75x6587x9f99
Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.eyuyan.com)
ProductName: x66f4x65b0x7a0bx5e8f
ProductVersion: 1.0.0.0
FileDescription: x672cx7a0bx5e8fx4e3ax8d75x6587x9f99x4e13x7528x8f6fx4ef6x66f4x65b0xff01
Translation: 0x0804 0x04b0

Generic PUA CO (PUA) also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.33555095
FireEyeGeneric.mg.a44be911d514055b
CAT-QuickHealTrojanpws.Qqpass.16554
McAfeeArtemis!A44BE911D514
ALYacTrojan.GenericKD.33555095
K7AntiVirusTrojan ( 005246d51 )
BitDefenderTrojan.GenericKD.33555095
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_80% (W)
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34100.3q0@aOyh5hmb
F-ProtW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0PCJ20
ClamAVWin.Malware.Zusy-6840460-0
GDataWin32.Application.PUPStudio.A
AegisLabTrojan.Win32.Kolovorot.lpUa
APEXMalicious
RisingMalware.Heuristic!ET#98% (RDMK:cmRtazpo489ULdCJmrGXmX60zdZZ)
Endgamemalicious (high confidence)
SophosGeneric PUA CO (PUA)
ComodoWorm.Win32.Dropper.RA@1qraug
TrendMicroTROJ_GEN.R002C0PCJ20
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.33555095 (B)
SentinelOneDFI – Malicious PE
CyrenW32/Agent.EW.gen!Eldorado
JiangminTrojanDropper.Binder.wn
MAXmalware (ai score=81)
Antiy-AVLGrayWare/Win32.FlyStudio.a
ArcabitTrojan.Generic.D2000297
SUPERAntiSpywareTrojan.Agent/Gen-OnlineGames
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
Ad-AwareTrojan.GenericKD.33555095
CylanceUnsafe
eGambitUnsafe.AI_Score_99%
FortinetW32/QQWare.A!tr
Cybereasonmalicious.4dbf88
Paloaltogeneric.ml

How to remove Generic PUA CO (PUA)?

Generic PUA CO (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment