PUA

How to remove “Generic PUA KD (PUA)”?

Malware Removal

The Generic PUA KD (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA KD (PUA) virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic PUA KD (PUA)?


File Info:

crc32: B6A63DF0
md5: 9ad448ed860f18cad9c76942a70d4e7e
name: tojpg.exe
sha1: a346e46fb28f42d3ce29ef144c3f51a8323132f8
sha256: 19bae9375dc2038ceaae76aa77ff63b4bd147098f2e08950ae8857a7eca0c0f5
sha512: 3ceb55184973183741a5f8abb83bab5523229e06dee02157c46ad1d0412f3affae0f3061f13b1753c8b490de8367fd46e6dac9cc6b7e913abd312d8216690683
ssdeep: 24576:4Nf4iQIXE5YRogGkcJZ9XC3V1RzVRE64jLiWehvC6DYBhGlG3ME:4x4iy5YRol7e+buK6Ddu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7b2cx4e00x5ba2x670dxff08www.d1kf.comxff09
FileVersion: 3.0.0.0
CompanyName: x7b2cx4e00x5ba2x670d
Comments: x6279x91cfx8f6cx6362JPGx56fex7247
ProductName: x6279x91cfx8f6cx6362JPGx56fex7247
ProductVersion: 3.0.0.0
FileDescription: x6279x91cfx8f6cx6362JPGx56fex7247
Translation: 0x0804 0x04b0

Generic PUA KD (PUA) also known as:

McAfeeArtemis!9AD448ED860F
CylanceUnsafe
K7GWTrojan ( 005246d51 )
K7AntiVirusTrojan ( 005246d51 )
F-ProtW32/OnlineGames.HG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ViRobotAdware.Onlinegames.1388544
Endgamemalicious (high confidence)
SophosGeneric PUA KD (PUA)
ComodoWorm.Win32.Dropper.RA@1qraug
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.th
Trapminemalicious.high.ml.score
CyrenW32/OnlineGames.HG.gen!Eldorado
Antiy-AVLGrayWare/Win32.FlyStudio.a
MicrosoftPUA:Win32/Presenoker
Acronissuspicious
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
SentinelOnestatic engine – malicious
FortinetRiskware/Application
CrowdStrikemalicious_confidence_100% (W)

How to remove Generic PUA KD (PUA)?

Generic PUA KD (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment