PUA

How to remove “Generic PUA HA (PUA)”?

Malware Removal

The Generic PUA HA (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA HA (PUA) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

mrantifun.net
www.bing.com

How to determine Generic PUA HA (PUA)?


File Info:

crc32: 3BAD4A62
md5: 4977ab5edb4117314038449600d24174
name: Godus-V2.2-Trainer-4-MrAntiFun.EXE
sha1: 70542b2064319c762e7aa4e15ce6bc69383e1996
sha256: 34a53a35773156f594d2c54f5b256ace688125202399c3b10b189051fd0a99f0
sha512: a3ca078fb421214b9df939510b92990d8ab1c418bd7b97e5396d7f7cb0e2bc4b5cdaa8b2e2f6741d08679a7ffe2e040b486ef6ad687159926e655beb6e391032
ssdeep: 98304:HHaT9sDNeEgxVpaajR26+pl0bpK8C69GuSPdl9Yj:n4VueR8pCdKo9yl6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic PUA HA (PUA) also known as:

CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7GWUnwanted-Program ( 004ba1a41 )
K7AntiVirusUnwanted-Program ( 004ba1a41 )
Invinceaheuristic
CyrenW32/CheatEngine.B.gen!Eldorado
SymantecTrojan.Gen.2
TrendMicro-HouseCallTROJ_SPNR.15A715
Paloaltogeneric.ml
GDataWin32.Riskware.Hacktool.D
SophosGeneric PUA HA (PUA)
TrendMicroTROJ_SPNR.15A715
McAfee-GW-EditionBehavesLike.Win32.PUPXAR.rc
EmsisoftApplication.GameHack (A)
SentinelOnestatic engine – malicious
F-ProtW32/CheatEngine.B.gen!Eldorado
JiangminTrojanDropper.Injector.aqkx
WebrootW32.Malware.Gen
Antiy-AVLTrojan[Packed]/Win32.PolyCrypt
Endgamemalicious (high confidence)
McAfeePUP-XAR-GC
AVwareTrojan.Win32.Generic!BT
MAXmalware (ai score=100)
WhiteArmorMalware.HighConfidence
PandaTrj/CI.A
ZonerTrojan.Cheatengine
ESET-NOD32a variant of Win32/HackTool.CheatEngine.AF potentially unsafe
YandexHackTool.CheatEngine!h2lP7QG9eRI
Cybereasonmalicious.064319
CrowdStrikemalicious_confidence_100% (D)

How to remove Generic PUA HA (PUA)?

Generic PUA HA (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment