PUA

Generic PUA DE (PUA) removal tips

Malware Removal

The Generic PUA DE (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA DE (PUA) virus can do?

  • Creates RWX memory
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Turkish
  • The binary likely contains encrypted or compressed data.
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
xred.mooo.com
freedns.afraid.org
a.tomx.xyz

How to determine Generic PUA DE (PUA)?


File Info:

crc32: 8CE5F77A
md5: 5bf770a2a49a0532d0f98329b4114574
name: 3.3.exe
sha1: 60c9a675ea27a79db27ea5fe8ca98041d8fecd2c
sha256: 9adc4246ee89dcfbe542a3a3276454f1ea15a6e0a0cedd718df89143b6158b27
sha512: d745a746ef470c18929c1778779aac193720d840b6f91d9ddd2ad1186a5b402ce439f3314679885b8d43c74244ffd0699bd45aaa398cf70b0a3739f38ee00331
ssdeep: 24576:ansJ39LyjbJkQFMhmC+6GD9KTfj/pc3eGd2Hk0kGU:ansHyjtk2MYC5GDAry3eGTF5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.0.0.4
CompanyName: Synaptics
LegalTrademarks:
Comments:
ProductName: Synaptics Pointing Device Driver
ProductVersion: 1.0.0.0
FileDescription: Synaptics Pointing Device Driver
OriginalFilename:
Translation: 0x041f 0x04e6

Generic PUA DE (PUA) also known as:

BkavW32.AIDetectVM.malware
DrWebTrojan.DownLoader22.9658
MicroWorld-eScanDropped:Trojan.GenericKD.32840913
FireEyeGeneric.mg.5bf770a2a49a0532
CAT-QuickHealSus.Nocivo.E0011
Qihoo-360Win32/Virus.Synaptics.A
McAfeeGenericRXCB-VC!5BF770A2A49A
CylanceUnsafe
VIPREBehavesLike.Win32.Malware.eah (mx-v)
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderDropped:Trojan.GenericKD.32840913
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.5ea27a
TrendMicroVirus.Win32.NAPWHICH.B
BitDefenderThetaGen:NN.ZelphiF.34106.pH0@aSNo@fkH
CyrenW32/Backdoor.OAZM-5661
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Delf-6899401-0
GDataDropped:Trojan.GenericKD.32840913
KasperskyBackdoor.Win32.DarkKomet.hqxy
AlibabaBackdoor:Win32/DarkKomet.f7dfdbcd
NANO-AntivirusTrojan.Win32.DarkKomet.fazbwq
AegisLabTrojan.Win32.DarkKomet.tp6k
AvastWin32:Zorex-E [Wrm]
RisingBackdoor.Agent!1.BF3D (CLOUD)
Ad-AwareDropped:Trojan.GenericKD.32840913
SophosGeneric PUA DE (PUA)
ComodoVirus.Win32.Agent.DE@74b38h
F-SecureTrojan:W97M/MaliciousMacro.GEN
ZillyaTrojan.Delf.Win32.76144
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.CryptDoma.th
Trapminesuspicious.low.ml.score
EmsisoftDropped:Trojan.GenericKD.32840913 (B)
IkarusVirus.Win32.Delf
F-ProtW32/Zorex.A
JiangminTrojan.Generic.bhoqf
WebrootW32.Malware.gen
AviraWORM/Dldr.Agent.gqrxn
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
ArcabitHEUR.VBA.Trojan.d
ZoneAlarmBackdoor.Win32.DarkKomet.hqxy
MicrosoftWorm:Win32/AutoRun.XXY!bit
AhnLab-V3Win32/Zorex.X1799
Acronissuspicious
ALYacDropped:Trojan.GenericKD.32840913
VBA32TScope.Trojan.Delf
MalwarebytesTrojan.Agent
ZonerTrojan.Win32.88102
ESET-NOD32Win32/Delf.NBX
TrendMicro-HouseCallVirus.Win32.NAPWHICH.B
TencentVirus.Win32.DarkKomet.a
YandexBackDoor.Optix!
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Delf.NBX!tr
AVGOther:Malware-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.121218.susgen

How to remove Generic PUA DE (PUA)?

Generic PUA DE (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment