PUA

Generic PUA LE (PUA) information

Malware Removal

The Generic PUA LE (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA LE (PUA) virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic PUA LE (PUA)?


File Info:

crc32: DBA982E0
md5: b2e7c80904fbb73a2b2f7db93b380f57
name: aotian_tjkd.exe
sha1: bb261f422dee01177426d6cd1f145ce21949987d
sha256: 7063344e68eddf606fbb855680f3694878f986f08fc9c4e4b36d38882a3858c1
sha512: c60bbe903e938e14d85913d6bfa48b5affa7b834f2b6e42e462cff648130db130ec715830412b1e23549f4d7ce64c47bd62afa986b98c430e7a5a5d1403ed5e2
ssdeep: 12288:PQUoKyTI8hgGNtpRDcvsQlIMgW/Ftu/yhb/MXujPNBdxLuwSlupySaDW/pV:zoKyTI8hgGNtrcEO/gWjuFAPNswIQmav
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x50b2x5929x6e38x620fx4e2dx5fc3
FileVersion: 3.0.0.0
CompanyName: x50b2x5929x6e38x620fx4e2dx5fc3
ProductName: x50b2x5929x5929x5251x72c2x5200
ProductVersion: 3.0.0.0
FileDescription: x50b2x5929x5929x5251x72c2x5200 install
Translation: 0x0804 0x03a8

Generic PUA LE (PUA) also known as:

FireEyeGeneric.mg.b2e7c80904fbb73a
CAT-QuickHealPUA.AgentRI.S8916463
McAfeeArtemis!B2E7C80904FB
CylanceUnsafe
K7AntiVirusAdware ( 004fef751 )
K7GWAdware ( 004fef751 )
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Malware-gen
GDataWin32.Application.Agent.B1S00I
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
AlibabaAdWare:Win32/Wews87.7bd1edae
NANO-AntivirusRiskware.Win32.Autoruner2.foqqzl
ViRobotAdware.Wews87.718528
RisingPUA.Wews87!8.642 (CLOUD)
SophosGeneric PUA LE (PUA)
ComodoApplicUnwnt@#18vyvk2wyj0zu
F-SecureAdware.ADWARE/Wews87.rywnd
DrWebWin32.HLLW.Autoruner2.33013
ZillyaAdware.Wews87.Win32.333
Invinceaheuristic
McAfee-GW-EditionArtemis!Trojan
IkarusPUA.Wews87
JiangminAdWare.Generic.ntwk
AviraADWARE/Wews87.gcmuy
Antiy-AVLGrayWare/Win32.Wews87
Endgamemalicious (high confidence)
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Agent.gen
MicrosoftPUA:Win32/CoinMiner
MAXmalware (ai score=51)
VBA32BScope.Adware.FileFinder
MalwarebytesPUP.Optional.Wews87
ESET-NOD32a variant of Win32/Wews87.B potentially unwanted
TencentWin32.Adware.Generic.Pgmp
FortinetAdware/Generic
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Generic PUA LE (PUA)?

Generic PUA LE (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment