PUA

Generic PUA IJ (PUA) removal guide

Malware Removal

The Generic PUA IJ (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA IJ (PUA) virus can do?

  • Presents an Authenticode digital signature
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Queries information on disks, possibly for anti-virtualization
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
api.ip138.com
a.tomx.xyz
ab.popodi.com
down.xiald.com
down.popodi.com
www.9973.com
xzqtj.xiald.com

How to determine Generic PUA IJ (PUA)?


File Info:

crc32: 967BF181
md5: a9303022ca291b28d9aff3584d8bca83
name: __________131_807585.exe
sha1: 89a23815b241a075344c5dcc4400da9a9ca0800c
sha256: cd2acf1d30d1311f9d2ba3e703e94863337c89f3717c1ef2b65924587f5d53db
sha512: 0e5e9e58f235c93f7390a9e19eb05d72f0e87a5c5d3ec8b9d9175e078da6419b375fa79943687624d52bbe76cd3fd473078e25a30078a8637f057851366956e6
ssdeep: 49152:GDxESbsNP1SPLn5crA7tdOYd4ECAuetadb7pHWnjSwfgU:vVNPaLn5cridrTueta9gnr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018
InternalName: x9ad8x901fx4e0bx8f7dx5668
FileVersion: 1.4.8.19902
CompanyName: x9ad8x901fx4e0bx8f7dx5668
ProductName: x9ad8x901fx4e0bx8f7dx5668
ProductVersion: 1,4,8,19902
FileDescription: x9ad8x901fx4e0bx8f7dx5668
OriginalFilename: Install.exe
Translation: 0x0804 0x04b0

Generic PUA IJ (PUA) also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.32816246
FireEyeTrojan.GenericKD.32816246
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeArtemis!A9303022CA29
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 004f38e41 )
BitDefenderTrojan.GenericKD.32816246
K7GWAdware ( 004f38e41 )
Invinceaheuristic
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
GDataTrojan.GenericKD.32816246
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
AlibabaAdWare:Win32/Softcnapp.e544e003
ViRobotAdware.Softcnapp.2488744.C
TencentMalware.Win32.Gencirc.10b72985
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.32816246 (B)
ComodoApplicUnwnt@#ctsqfwlxcuo6
DrWebAdware.Softcnapp.119
ZillyaAdware.Agent.Win32.145365
McAfee-GW-EditionArtemis!PUP
SophosGeneric PUA IJ (PUA)
CyrenW32/Trojan.SWOA-1486
JiangminAdware.Agent.akhv
ArcabitTrojan.Generic.D1F4BC76
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Generic
MicrosoftPUA:Win32/CoinMiner
AhnLab-V3PUP/Win32.Softcnapp.R290955
VBA32BScope.Adware.Puwaders
ALYacTrojan.GenericKD.32816246
Ad-AwareTrojan.GenericKD.32816246
MalwarebytesPUP.Optional.Softcnapp
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Softcnapp.J potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002H0CCB20
RisingAdware.Downloader!1.BBEC (CLOUD)
SentinelOneDFI – Suspicious PE
FortinetAdware/Agent
AVGWin32:AdwareX-gen [Adw]
CrowdStrikewin/malicious_confidence_60% (D)
MaxSecureTrojan.Malware.74548417.susgen

How to remove Generic PUA IJ (PUA)?

Generic PUA IJ (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment