PUA

Should I remove “Generic PUA MA (PUA)”?

Malware Removal

The Generic PUA MA (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA MA (PUA) virus can do?

  • Presents an Authenticode digital signature
  • A process created a hidden window
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic PUA MA (PUA)?


File Info:

crc32: ACB93EAF
md5: 187b2c04d0929c3542465f9f2ba350fe
name: tnews-5.exe
sha1: c0b2ee5040c4264c58c7cd265abb86005e754577
sha256: 488a85d26662ac24404457eefad2ff4d376c7456abb6685c80b0604190f78dea
sha512: 95df351ed59999e418f2e36c94c1e204a20c296031b95663f2dc927407b5b63697967d1973dd1cf5a1aa4634bb890c1a887e958b8348c0c3ff301612fb33cdc8
ssdeep: 24576:hedCd3+G9lyKPFmsw4Esyqjx4zCWCNY6J66zkh/mAOiSm61Nfk:hOtGHyYsC4WxpYDh/mAQm6Lfk
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2010-2018
ProductVersion: 2018.12.14.5
FileVersion: 2018.12.14.5
FileDescription: x5bd2x6885x7279x60e0
Translation: 0x0804 0x04b0

Generic PUA MA (PUA) also known as:

BkavW32.HfsAdware.C51A
MicroWorld-eScanGen:Variant.Application.Strictor.178792
CAT-QuickHealTrojan.GenericPMF.S4676898
McAfeeGenericRXGV-OM!187B2C04D092
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabAdware.Win32.KuaiZip.2!c
SangforMalware
K7AntiVirusTrojan ( 00549c081 )
BitDefenderGen:Variant.Application.Strictor.178792
K7GWAdware ( 004f1e691 )
CrowdStrikewin/malicious_confidence_100% (D)
Invinceaheuristic
CyrenW32/S-9a239792!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/KuaiZip.B potentially unwanted
APEXMalicious
Kasperskynot-a-virus:HEUR:AdWare.Win32.KuziTui.gen
AlibabaBackdoor:Win32/KZip.c430ccd5
NANO-AntivirusRiskware.Win32.KuaiZip.fvrahs
SUPERAntiSpywarePUP.KuaiZip/Variant
Ad-AwareGen:Variant.Application.Strictor.178792
EmsisoftGen:Variant.Application.Strictor.178792 (B)
ComodoApplication.Win32.KuaiZip.BG@81beht
F-SecurePotentialRisk.PUA/KuaiZip.Gen
DrWebProgram.Kuaizip.1
ZillyaAdware.KuaiZip.Win32.127
TrendMicroTROJ_GEN.R002C0OCG20
McAfee-GW-EditionGenericRXGV-OM!187B2C04D092
MaxSecureWin.MxResIcn.Heur.Gen
FireEyeGeneric.mg.187b2c04d0929c35
SophosGeneric PUA MA (PUA)
F-ProtW32/S-9a239792!Eldorado
JiangminAdWare.KuaiZip.cs
WebrootW32.Malware.gen
AviraPUA/KuaiZip.Gen
FortinetAdware/KuaiZip
Antiy-AVLGrayWare[AdWare]/Win32.KuaiZip
Endgamemalicious (high confidence)
ArcabitTrojan.Application.Strictor.D2BA68
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.KuziTui.gen
MicrosoftPUA:Win32/KuaiZip
AhnLab-V3PUP/Win32.KuaiZip.C2898971
MAXmalware (ai score=99)
VBA32Adware.KuaiZip
MalwarebytesAdware.Kuaiba
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0OCG20
RisingPUF.KuaiZip!8.2F40 (C64:YzY0Ok3qJz/L905A)
YandexPUA.KuaiZip!
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_70%
GDataGen:Variant.Application.Strictor.178792
AVGFileRepMalware
Cybereasonmalicious.4d0929
AvastFileRepMalware

How to remove Generic PUA MA (PUA)?

Generic PUA MA (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment