PUA

About “Generic PUA EH (PUA)” infection

Malware Removal

The Generic PUA EH (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA EH (PUA) virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
tjv1.wn51.com

How to determine Generic PUA EH (PUA)?


File Info:

crc32: 015C3DEB
md5: 664c1be867b43a9bb30011b7e955971b
name: setup_wnyskb017.exe
sha1: 47cd656239104f4a240f8fb2c554c2d63042bee2
sha256: 4300cc47451181b3a65b8f458e167dcac7cb6ec678ec6291441df577a7c204dd
sha512: afed3b526e3d308faeb96d01df0c51d669570a24bbb15eff16f6afa9b51602768aa76828806afa197ffc3d5bd2365913cc72c5a73aa905c76e11899b7853bf01
ssdeep: 196608:xlUY5OnwTYDtuyU3BbTPAutlgcB5AqGVR9aM2V9ia5:LU/vDtuF31TfEXJ9af+o
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2019
InternalName: x4e07x80fdx538bx7f29
FileVersion: 1.4.2.19924
CompanyName: x4e07x80fdx538bx7f29
ProductName: x4e07x80fdx538bx7f29
ProductVersion: 1,4,2,19924
FileDescription: x4e07x80fdx538bx7f29
OriginalFilename: Install.exe
Translation: 0x0804 0x04b0

Generic PUA EH (PUA) also known as:

BkavW32.HfsAdware.DA20
DrWebAdware.Softcnapp.80
MicroWorld-eScanTrojan.GenericKD.42814722
FireEyeGeneric.mg.664c1be867b43a9b
CAT-QuickHealTrojan.GenericRI.S11519324
McAfeeGenericRXAA-AA!664C1BE867B4
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 004d9e2c1 )
BitDefenderTrojan.GenericKD.42814722
K7GWAdware ( 004d9e2c1 )
CyrenW32/Application.DKJL-4798
APEXMalicious
AvastWin32:Adware-gen [Adw]
GDataTrojan.GenericKD.42814722
Kasperskynot-a-virus:HEUR:AdWare.Win32.Burden.gen
AlibabaAdWare:Win32/Softcnapp.50a18a4c
NANO-AntivirusRiskware.Win32.Softcnapp.gzvpfa
ViRobotAdware.Softcnapp.9745520
RisingAdware.Softcnapp!1.B5FE (CLASSIC)
Ad-AwareTrojan.GenericKD.42814722
SophosGeneric PUA EH (PUA)
F-SecurePotentialRisk.PUA/Softcnapp.Gen
ZillyaAdware.Burden.Win32.215
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftTrojan.GenericKD.42814722 (B)
IkarusPUA.Softcnapp
JiangminAdWare.Burden.cl
MaxSecureTrojan.Malware.74168012.susgen
AviraPUA/Softcnapp.Gen
MAXmalware (ai score=99)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D28D4D02
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Burden.gen
MicrosoftPUA:Win32/Softcnapp
AhnLab-V3PUP/Win32.Softcnapp.R275230
VBA32BScope.Adware.Softcnapp
ALYacTrojan.GenericKD.42814722
MalwarebytesAdware.ChinAd
ESET-NOD32a variant of Win32/Softcnapp.J potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002H0CKO19
TencentMalware.Win32.Gencirc.10b0a7e3
YandexPUA.Burden!
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetAdware/Burden
WebrootW32.Adware.Gen
AVGWin32:Adware-gen [Adw]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic PUA EH (PUA)?

Generic PUA EH (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment