Categories: PUA

Generic PUA GD (PUA) (file analysis)

The Generic PUA GD (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA GD (PUA) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic PUA GD (PUA)?


File Info:

crc32: F3FAC5D3md5: 7767e15bf9796f199bf53acb2fee0bb6name: 100114382_7767e15bf9796f199bf53acb2fee0bb6.exesha1: 633b5a57b82b52e13b7add672d80647a91ac3cfbsha256: 3d3483a35689bec9fbcfdd5ebe015382ba269eb743c750d4fcae5e43fc18251dsha512: a30cfc7f2b561e604fa7f1bb261f3804f7f38f4d2ff473d0d03f1684f1f1600ee05d8910fccaf535eab9e91e7beeee02b298440d84427041ee28e302f9a62953ssdeep: 98304:DE4jUleZPvO2uFIoIynJTsYsSwV2l/J0H2B0cq94u6yMpDm2goNuM4kTGo:DjUsPvOpFIKYSg4/WPh6yMw0wM4Ftype: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

LegalCopyright: x7248x6743x6240x6709(C) x963fx5609 x514dx8d23x6761x6b3exff1a x672cx8f6fx4ef6x7248x6743x4ebax7533x660ex4e0dx5bf9x672cx8f6fx4ef6x4ea7x54c1x7684x5b89x88c5x3001x4f7fx7528x63d0x4f9bx4efbx4f55x660ex793ax7684x548cx9690x542bx7684x4fddx8bc1x3002x4e0dx5bf9x8f6fx4ef6x4f7fx7528x4e2dx6240x9047x5230x7684x4efbx4f55x7406x8bbax4e0ax7684x6216x5b9ex9645x4e0ax7684x635fx5931x627fx62c5x8d23x4efbx3002 x66f4x591ax4fe1x606fx8bf7x8bbfx95eexff1ahttp://www.443w.com x8054x7cfbx4f5cx8005xff1a cctvw0m1@126.com QQ: 1006018660FileVersion: 1.1.0.0CompanyName: x963fx5609 www.443w.comComments: x963fx5609 www.443w.comProductName: x7b80x5355x81eax89e3x538bx7a0bx5e8fProductVersion: 1.1.0.0FileDescription: x7b80x5355x81eax89e3x538bx7a0bx5e8fTranslation: 0x0804 0x04b0

Generic PUA GD (PUA) also known as:

McAfee Artemis!7767E15BF979
Cylance Unsafe
Zillya Backdoor.Poison.Win32.91362
CrowdStrike win/malicious_confidence_100% (D)
Invincea heuristic
F-Prot W32/OnlineGames.HI.gen!Eldorado
Symantec PUA.Gen.4
APEX Malicious
Paloalto generic.ml
GData Win32.Trojan.Agent.YXUKMV
NANO-Antivirus Virus.Win32.Agent.dvixmz
AegisLab Trojan.Win32.Generic.4!c
Endgame malicious (high confidence)
Emsisoft Trojan.GenericKD.32644185 (B)
Comodo Malware@#1c8t71wiotax9
VIPRE Trojan.Win32.OnlineGames
TrendMicro TROJ_GEN.R002C0PDS19
McAfee-GW-Edition BehavesLike.Win32.Dropper.tc
FireEye Generic.mg.7767e15bf9796f19
Sophos Generic PUA GD (PUA)
Cyren W32/OnlineGames.HI.gen!Eldorado
Webroot W32.Malware.Gen
Microsoft Trojan:Win32/Occamy.C
BitDefenderTheta Gen:NN.ZexaF.32250.@l0faq2jZYnb
Malwarebytes RiskWare.FlyStudio
Panda Trj/CI.A
ESET-NOD32 a variant of Win32/Packed.FlyStudio.AA potentially unwanted
TrendMicro-HouseCall TROJ_GEN.R002C0PDS19
SentinelOne DFI – Suspicious PE
Fortinet Riskware/Flyagent
AVG Win32:Malware-gen
Cybereason malicious.7b82b5
Avast Win32:Malware-gen

How to remove Generic PUA GD (PUA)?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

What is “Trojan:Win32/Zenpak.ASAF!MTB”?

The Trojan:Win32/Zenpak.ASAF!MTB is considered dangerous by lots of security experts. When this infection is active,…

5 mins ago

Should I remove “Zusy.498877”?

The Zusy.498877 is considered dangerous by lots of security experts. When this infection is active,…

26 mins ago

PUA.AgentPMF.S31839339 (file analysis)

The PUA.AgentPMF.S31839339 is considered dangerous by lots of security experts. When this infection is active,…

35 mins ago

Barys.431081 (B) removal guide

The Barys.431081 (B) is considered dangerous by lots of security experts. When this infection is…

40 mins ago

MSIL/DllInject.XF potentially unsafe information

The MSIL/DllInject.XF potentially unsafe is considered dangerous by lots of security experts. When this infection…

51 mins ago

Virus.Win32.Luder.B malicious file

The Virus.Win32.Luder.B is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago