PUA

Generic PUA KE (PUA) (file analysis)

Malware Removal

The Generic PUA KE (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA KE (PUA) virus can do?

  • Creates RWX memory
  • Starts servers listening on 0.0.0.0:80
  • Creates a hidden or system file
  • Anomalous binary characteristics

Related domains:

www.rejetto.com

How to determine Generic PUA KE (PUA)?


File Info:

crc32: 43C396A2
md5: c15e990e5081d20e1afb32017b06dbd6
name: hfs24rc4.exe
sha1: a4b07917c7f7a010ac74c2c1abaee259b6262eec
sha256: 1cfb311139c5198169fd308aa825ae4f6924cd67dcb1d83815a8b0ccb57a320b
sha512: e8380bb9b616339633d3144214286ab9fda3e08121a51614f53b00096d0c5664659d35af442580a0baad667114fb72421e0c2b415f58c427c0a9c879defd107b
ssdeep: 49152:XKvSddTCVmyhsTyY5l0wseAXY9H6rR65KtlTr1z+iD98ZcR7SZ:XKvSL+myhsmY30w5OCwfKs
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002 Massimo Melina (www.rejetto.com)
InternalName: HFS
FileVersion: 2.4.0.0
CompanyName: rejetto
LegalTrademarks:
Comments:
ProductName: Http File Server
ProductVersion: 2.4
FileDescription:
OriginalFilename: hfs.exe
Translation: 0x0410 0x04e4

Generic PUA KE (PUA) also known as:

McAfeeArtemis!C15E990E5081
CylanceUnsafe
RisingPUA.Presenoker!8.F608 (CLOUD)
ZillyaTrojan.ServerWeb.Win32.32
McAfee-GW-EditionBehavesLike.Win32.Dropper.vh
SophosGeneric PUA KE (PUA)
IkarusPUA.Server-Web.Hfs
CyrenW32/Trojan.ZTNT-0752
eGambitUnsafe.AI_Score_71%
Endgamemalicious (high confidence)
MicrosoftPUA:Win32/Presenoker
ESET-NOD32a variant of Win32/Server-Web.HFS.A potentially unsafe
FortinetRiskware/Generic_PUA_KE

How to remove Generic PUA KE (PUA)?

Generic PUA KE (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment