PUA

About “Generic PUA IM (PUA)” infection

Malware Removal

The Generic PUA IM (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA IM (PUA) virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Tries to unhook or modify Windows functions monitored by Cuckoo

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic PUA IM (PUA)?


File Info:

crc32: DE56E1AE
md5: 8229341814c781b4dd62fbe2ca8e692e
name: ____________7.6___.exe
sha1: 8cb7f37a36669289dbed09755556da2e4d79741b
sha256: 52a5e13a191fc558f3333d6726d8e624e015cd1f94d8c8a53db6016d3bda2914
sha512: 00bb52521f7946feb9af3f7056d3e1c27e784ec8b064826e4dd44ef85c867be615537a0a442405c41b33360b2ddffda39d0f2cd5280813620486f4b7b3b7b178
ssdeep: 24576:autvvoxgV75k7z37mGB2fu1UFNMX4dLKMkJZKibp1HMhzadvA6Wvp2HJIrY470pB:aGv0LmGxUFuVtJjdOau6WiJILGYd/Vo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x4f5cx8005x7248x6743x6240x6709 x8bf7x5c0ax91cdx5e76x4f7fx7528x6b63x7248
FileVersion: 1.0.0.0
Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.eyuyan.com)
ProductName: x6613x8bedx8a00x7a0bx5e8f
ProductVersion: 1.0.0.0
FileDescription: x6613x8bedx8a00x7a0bx5e8f
Translation: 0x0804 0x04b0

Generic PUA IM (PUA) also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanGen:Heur.PWSIME.3
FireEyeGeneric.mg.8229341814c781b4
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 005246d51 )
BitDefenderGen:Heur.PWSIME.3
K7GWTrojan ( 00013a151 )
Cybereasonmalicious.814c78
F-ProtW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Malware.Onlinegames-6629257-0
GDataWin32.Application.PUPStudio.A
Kasperskynot-a-virus:RiskTool.Win32.IMEStartup.ah
AlibabaRiskWare:Win32/IMEStartup.d1248a45
TencentWin32.Trojan.Imeinject.Dxcr
Endgamemalicious (high confidence)
SophosGeneric PUA IM (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.wh
Trapminemalicious.moderate.ml.score
EmsisoftGen:Heur.PWSIME.3 (B)
SentinelOneDFI – Malicious PE
CyrenW32/Agent.EW.gen!Eldorado
JiangminTrojan/PSW.QQPass.mra
MaxSecureTrojan.Malware.300983.susgen
Antiy-AVLGrayWare/Win32.FlyStudio.a
ArcabitTrojan.PWSIME.3
SUPERAntiSpywareTrojan.Agent/Gen-OnlineGames
ZoneAlarmnot-a-virus:RiskTool.Win32.IMEStartup.ah
MicrosoftTrojan:Win32/Wacatac.D!ml
Acronissuspicious
VBA32BScope.Trojan.Tiggre
ALYacGen:Heur.PWSIME.3
Ad-AwareGen:Heur.PWSIME.3
MalwarebytesSpyware.OnlineGames
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R01FH0CDH20
RisingMalware.Heuristic!ET#96% (RDMK:cmRtazrrq1VfzW19lbHFbSG4iCT+)
MAXmalware (ai score=89)
eGambitUnsafe.AI_Score_100%
FortinetW32/QQWare.A!tr
BitDefenderThetaGen:NN.ZexaF.34106.it0@aGLFtHjb
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM07.1.9B7B.Malware.Gen

How to remove Generic PUA IM (PUA)?

Generic PUA IM (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment