PUA

Generic PUA JM (PUA) information

Malware Removal

The Generic PUA JM (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA JM (PUA) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Starts servers listening on 0.0.0.0:5650, :0
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

rmansys.ru

How to determine Generic PUA JM (PUA)?


File Info:

crc32: B5F01C0B
md5: 80df2f0d4da5e61f4341c4d971170395
name: 2a4094a2133837df.exe
sha1: 4246048db2e697a05f8dc252e3cb60f7ce83832a
sha256: 915738e4e4df8462f006d169a1cdebc3f311f7250b794281f78fa24d90586e4b
sha512: 8a78824845d3b5f235028dd19107a6a9469f5f1bb4b18d7e41e54e6aff1d76157e0866c1cdb6d0d46029bca4307afc501a50f04d03926902ff96d8ca44acf069
ssdeep: 98304:b2tpzpptdlPk/vq1FXRF7LOmt64dcn1mx71J/T+BXuBFBrEy:b8tdcq1FXRxZtcnAJ1REXsBIy
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generic PUA JM (PUA) also known as:

MicroWorld-eScanTrojan.ScriptKD.4412
CAT-QuickHealHackTool.Rabased
McAfeeArtemis!B8667A1E8456
MalwarebytesPUP.Optional.RemoteUtilities
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 004f35231 )
K7GWTrojan ( 004f35231 )
Invinceaheuristic
BaiduWin32.Trojan.WisdomEyes.16070401.9500.9943
CyrenW32/Trojan.MBDS-0756
SymantecML.Attribute.HighConfidence
ESET-NOD32BAT/RA-based.CX
TrendMicro-HouseCallTROJ_GE.EDF1590A
ClamAVWin.Trojan.Generickd-4341
GDataTrojan.ScriptKD.4412
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.ScriptKD.4412
NANO-AntivirusTrojan.Script.RMS.enpelx
AegisLabTroj.W32.Generic!c
AvastWin32:PUP-gen [PUP]
Endgamemalicious (moderate confidence)
EmsisoftTrojan.ScriptKD.4412 (B)
ComodoTrojWare.Win32.Generic.usubc
F-SecureGen:Variant.Graftor.316246
DrWebVBS.Starter.65
ZillyaTrojan.GenericKD.Win32.1712
TrendMicroTROJ_GE.EDF1590A
McAfee-GW-EditionBehavesLike.Win32.Obfuscated.wc
SophosGeneric PUA JM (PUA)
Ikarusnot-a-virus:RemoteAdmin.Win32.RMS
JiangminRemoteAdmin.RMS.w
AviraTR/Dropper.Gen
Antiy-AVLRiskWare[RemoteAdmin]/Win32.RMS
ArcabitTrojan.ScriptKD.D113C
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftHackTool:Win32/Rabased
ALYacTrojan.ScriptKD.4412
AVwareTrojan.Win32.Generic!BT
VBA32Backdoor.RMS
RisingTrojan.Generic (cloud:tS6cZa3tQGQ)
YandexTrojan.InstallRadmin.B
SentinelOnestatic engine – malicious
FortinetRiskware/RemoteAdmin_RemoteUtilities
Ad-AwareTrojan.ScriptKD.4412
AVGWin32:PUP-gen [PUP]
PandaTrj/CI.A
CrowdStrikemalicious_confidence_100% (D)
Qihoo-360HEUR/QVM11.1.FDD8.Malware.Gen

How to remove Generic PUA JM (PUA)?

Generic PUA JM (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment