PUA

How to remove “Generic PUA DO (PUA)”?

Malware Removal

The Generic PUA DO (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA DO (PUA) virus can do?

  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Sniffs keystrokes
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic PUA DO (PUA)?


File Info:

crc32: D4D7A8FE
md5: b9efcbe0dfa358df2e40f076cb32b11c
name: Mafia-2-Update-5-Plus-22-Trainer.EXE
sha1: 3e43151d31d9e911a958a74edbbd6ffbb980162a
sha256: 139fd82a4b516b22f826a08d7c079ae938475c2824dbb8276d67c6513a95462d
sha512: 98af4a51ad1103f2c1d7fb2e6f4067782872424322ab3741d8cb4c706f44514bd2f04aab37de13079ef6a8f5ef17cb843d4426e6a9e23d0d252c6aeb3009c1dc
ssdeep: 98304:9b7N6ZJYLDFj/oDOqUyfozcBdzsPEVqYON:998SVoiqpoidzrVqYON
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic PUA DO (PUA) also known as:

MicroWorld-eScanTrojan.GenericKD.41891293
CAT-QuickHealDropper.Jeefo.YY5
McAfeeArtemis!B9EFCBE0DFA3
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderTrojan.GenericKD.41891293
K7GWUnwanted-Program ( 004ba1a41 )
K7AntiVirusUnwanted-Program ( 004ba1a41 )
ArcabitTrojan.Generic.D27F35DD
CyrenW32/CheatEngine.C.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/HackTool.CheatEngine.AF potentially unsafe
AlibabaHackTool:Win32/CheatEngine.61194f48
AegisLabTrojan.Win64.Cobalt.tpMn
Ad-AwareTrojan.GenericKD.41891293
EmsisoftTrojan.GenericKD.41891293 (B)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.PUPXAR.rc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.b9efcbe0dfa358df
SophosGeneric PUA DO (PUA)
SentinelOneDFI – Malicious PE
F-ProtW32/CheatEngine.C.gen!Eldorado
JiangminTrojanSpy.KeyLogger.lsz
WebrootW32.Malware.Gen
MAXmalware (ai score=100)
Antiy-AVLHackTool[Hoax]/Win32.CheatEngine.a
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34082.@xW@aOV70Tki
ALYacTrojan.GenericKD.41891293
RisingTrojan.Wacatac!8.10C01 (CLOUD)
YandexHackTool.CheatEngine!h2lP7QG9eRI
eGambitUnsafe.AI_Score_99%
GDataWin32.Riskware.Hacktool.D
Paloaltogeneric.ml

How to remove Generic PUA DO (PUA)?

Generic PUA DO (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment