PUA

Generic PUA IL (PUA) malicious file

Malware Removal

The Generic PUA IL (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA IL (PUA) virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.

Related domains:

downloader.downerapi.com

How to determine Generic PUA IL (PUA)?


File Info:

crc32: D5B3A0C5
md5: 2914717cd5c02451935027d75448ef98
name: bandizip______________________034392394.exe
sha1: 8b861c81bd78791e7d48c5b142caf206b1dd7524
sha256: 831178f1a0bcd4c756f96bf5b51816b53db2eeedd151266eb964298d6c3b98db
sha512: e0d56ea2f35e41b747019ed1237002928c3422e0638ceac392d480a414f99fdc2bd67f42d4a2bc3c6b91403f745901f7e84200e4072a33ad4864f0689699f99a
ssdeep: 24576:YTdg1j6McsAlm0RnE1U2Npc7mUFZWAxOKDenSSHAYt+grVxdrtR5wQdY:Ypg1GENoBj1KnRg4Vj5R5wQdY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018
InternalName: FastDownloader.exe
FileVersion: 3.2.0.8
CompanyName: -
ProductName: x8f6fx4ef6x4e0bx8f7dx5668
ProductVersion: 3.2.0.8
FileDescription: x8f6fx4ef6x4e0bx8f7dx5668
OriginalFilename: FastDownloader.exe
Translation: 0x0804 0x04b0

Generic PUA IL (PUA) also known as:

MicroWorld-eScanGen:Variant.Razy.558009
FireEyeGeneric.mg.2914717cd5c02451
McAfeeGenericRXAA-AA!2914717CD5C0
CylanceUnsafe
K7AntiVirusRiskware ( 00543a2b1 )
BitDefenderGen:Variant.Razy.558009
K7GWRiskware ( 00543a2b1 )
TrendMicroPUA.Win32.Downer.USXVPAM20
APEXMalicious
GDataGen:Variant.Razy.558009
ViRobotAdware.Downer.1132384
Endgamemalicious (high confidence)
EmsisoftApplication.Downloader (A)
ComodoMalware@#1yjlwmif49gfr
ZillyaTool.Downer.Win32.46
Invinceaheuristic
McAfee-GW-EditionArtemis!Trojan
SophosGeneric PUA IL (PUA)
IkarusPUA.RiskWare.Downer
CyrenW32/Trojan.NLCZ-5503
WebrootW32.Adware.Gen
Antiy-AVLTrojan/Win32.Detplock
MicrosoftPUA:Win32/Downer
AhnLab-V3PUP/Win32.Generic.C3478818
MAXmalware (ai score=99)
MalwarebytesPUP.Optional.FastDownloader
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/RiskWare.Downer.A
TrendMicro-HouseCallPUA.Win32.Downer.USXVPAM20
RisingAdware.Downloader!1.BD64 (CLOUD)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_98%
FortinetRiskware/Downer
AVGFileRepMalware [PUP]
Paloaltogeneric.ml
MaxSecureTrojan.Malware.74682189.susgen

How to remove Generic PUA IL (PUA)?

Generic PUA IL (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment