PUA

Generic PUA GO (PUA) removal tips

Malware Removal

The Generic PUA GO (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA GO (PUA) virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)

Related domains:

w.nanweng.cn

How to determine Generic PUA GO (PUA)?


File Info:

crc32: 4D593859
md5: ceb54f199e7ec56c3931044779e50cf8
name: E4B88BE8BDBDE599A8.exe
sha1: 6ea0abfe6d755a55ad54919e6224bb08fddd343c
sha256: c1ea3c6d8f466ca7ea32adbd92885b35af26de7608d61430f0b04fd2a2fa18da
sha512: 23cb6ce463b76ad859c87ffeae3c5b282b3a03292087b029a0de9721a375b1cb3584962335dd739bdc981e4cbe0cd8e8e459177e89c00297dc524d25c02807b9
ssdeep: 24576:g7WGksNMSumx86mbyZDXj7mUOHX2Jy1xBz9SwTtZsSomHG0txdk:Xmx86Dz03q4Z3DHG0Tdk
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: x667ax80fdx4e0bx8f7dx5668.exe
FileVersion: 5.0.0.0318
ProductName: x667ax80fdx4e0bx8f7dx5668.exe
ProductVersion: 5.0.0.0318
FileDescription: x667ax80fdx4e0bx8f7dx5668
OriginalFilename: x667ax80fdx4e0bx8f7dx5668.exe
Translation: 0x0804 0x04b0

Generic PUA GO (PUA) also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.33563167
FireEyeGeneric.mg.ceb54f199e7ec56c
McAfeeArtemis!CEB54F199E7E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderTrojan.GenericKD.33563167
K7GWAdware ( 005105151 )
K7AntiVirusAdware ( 005105151 )
F-ProtW32/S-9ae944ef!Eldorado
AvastWin32:Adware-gen [Adw]
GDataTrojan.GenericKD.33563167
Kasperskynot-a-virus:Downloader.Win32.Agent.mgbc
AlibabaDownloader:Win32/Qjwmonkey.32e45db5
RisingAdware.Downloader!1.BDCA (CLASSIC)
Endgamemalicious (high confidence)
SophosGeneric PUA GO (PUA)
ComodoApplicUnwnt@#14l7upywahb36
F-SecureAdware.ADWARE/AD.QjwMonkey
DrWebAdware.Qjwmonkey.168
ZillyaAdware.Qjwmonkey.Win32.630
Invinceaheuristic
McAfee-GW-EditionArtemis!PUP
EmsisoftTrojan.GenericKD.33563167 (B)
IkarusPUA.Qjwmonkey
CyrenW32/S-9ae944ef!Eldorado
JiangminDownloader.Agent.myu
MaxSecureTrojan.Malware.121218.susgen
AviraADWARE/AD.QjwMonkey.dneew
WebrootW32.Adware.Gen
Antiy-AVLRiskWare[Downloader]/Win32.Agent
ArcabitTrojan.Generic.D200221F
SUPERAntiSpywareAdware.Qjwmonkey/Variant
ZoneAlarmnot-a-virus:Downloader.Win32.Agent.mgbc
MicrosoftPUA:Win32/Qjwmonkey
AhnLab-V3PUP/Win32.Installer.C4021483
VBA32BScope.Adware.Qjwmonkey
ALYacTrojan.GenericKD.33563167
MAXmalware (ai score=96)
Ad-AwareTrojan.GenericKD.33563167
MalwarebytesAdware.Qjwmonkey
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Adware.Qjwmonkey.H
TrendMicro-HouseCallTROJ_GEN.R049H0CCO20
TencentMalware.Win32.Gencirc.10b96896
YandexPUA.Qjwmonkey!
eGambitUnsafe.AI_Score_100%
FortinetW32/Qjwmonkey.KD!tr
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Generic PUA GO (PUA)?

Generic PUA GO (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment