PUA

Generic PUA GD (PUA) (file analysis)

Malware Removal

The Generic PUA GD (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA GD (PUA) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic PUA GD (PUA)?


File Info:

crc32: F3FAC5D3
md5: 7767e15bf9796f199bf53acb2fee0bb6
name: 100114382_7767e15bf9796f199bf53acb2fee0bb6.exe
sha1: 633b5a57b82b52e13b7add672d80647a91ac3cfb
sha256: 3d3483a35689bec9fbcfdd5ebe015382ba269eb743c750d4fcae5e43fc18251d
sha512: a30cfc7f2b561e604fa7f1bb261f3804f7f38f4d2ff473d0d03f1684f1f1600ee05d8910fccaf535eab9e91e7beeee02b298440d84427041ee28e302f9a62953
ssdeep: 98304:DE4jUleZPvO2uFIoIynJTsYsSwV2l/J0H2B0cq94u6yMpDm2goNuM4kTGo:DjUsPvOpFIKYSg4/WPh6yMw0wM4F
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

LegalCopyright: x7248x6743x6240x6709(C) x963fx5609 x514dx8d23x6761x6b3exff1a x672cx8f6fx4ef6x7248x6743x4ebax7533x660ex4e0dx5bf9x672cx8f6fx4ef6x4ea7x54c1x7684x5b89x88c5x3001x4f7fx7528x63d0x4f9bx4efbx4f55x660ex793ax7684x548cx9690x542bx7684x4fddx8bc1x3002x4e0dx5bf9x8f6fx4ef6x4f7fx7528x4e2dx6240x9047x5230x7684x4efbx4f55x7406x8bbax4e0ax7684x6216x5b9ex9645x4e0ax7684x635fx5931x627fx62c5x8d23x4efbx3002 x66f4x591ax4fe1x606fx8bf7x8bbfx95eexff1ahttp://www.443w.com x8054x7cfbx4f5cx8005xff1a cctvw0m1@126.com QQ: 1006018660
FileVersion: 1.1.0.0
CompanyName: x963fx5609 www.443w.com
Comments: x963fx5609 www.443w.com
ProductName: x7b80x5355x81eax89e3x538bx7a0bx5e8f
ProductVersion: 1.1.0.0
FileDescription: x7b80x5355x81eax89e3x538bx7a0bx5e8f
Translation: 0x0804 0x04b0

Generic PUA GD (PUA) also known as:

McAfeeArtemis!7767E15BF979
CylanceUnsafe
ZillyaBackdoor.Poison.Win32.91362
CrowdStrikewin/malicious_confidence_100% (D)
Invinceaheuristic
F-ProtW32/OnlineGames.HI.gen!Eldorado
SymantecPUA.Gen.4
APEXMalicious
Paloaltogeneric.ml
GDataWin32.Trojan.Agent.YXUKMV
NANO-AntivirusVirus.Win32.Agent.dvixmz
AegisLabTrojan.Win32.Generic.4!c
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.32644185 (B)
ComodoMalware@#1c8t71wiotax9
VIPRETrojan.Win32.OnlineGames
TrendMicroTROJ_GEN.R002C0PDS19
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.7767e15bf9796f19
SophosGeneric PUA GD (PUA)
CyrenW32/OnlineGames.HI.gen!Eldorado
WebrootW32.Malware.Gen
MicrosoftTrojan:Win32/Occamy.C
BitDefenderThetaGen:NN.ZexaF.32250.@l0faq2jZYnb
MalwarebytesRiskWare.FlyStudio
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0PDS19
SentinelOneDFI – Suspicious PE
FortinetRiskware/Flyagent
AVGWin32:Malware-gen
Cybereasonmalicious.7b82b5
AvastWin32:Malware-gen

How to remove Generic PUA GD (PUA)?

Generic PUA GD (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment