PUA

About “Generic PUA MH (PUA)” infection

Malware Removal

The Generic PUA MH (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA MH (PUA) virus can do?

  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic PUA MH (PUA)?


File Info:

crc32: 410C4DF3
md5: 090064bee7343cdd519b960a6df3d61a
name: setup.exe
sha1: c752430460de18e91b3c0470a2b5a3463b1c2db6
sha256: b57c14e66927e773f929664c0987b2be55da555a84c9336a0c2e8d5a7f8586fc
sha512: 07135e2c9fff1006cc8579f4e85948b769b7d3a45b411ca05e0517e1ff045eab9881791463a2c13985ad0948a7c3199c75f4285b4272e832570e21043694281a
ssdeep: 98304:mhAUccw7wadlG48Lm8cM3dNNdIDi2w3Vpmtp23WRZOSq2CIF:c7w7wapPe2w3Ag3W2SFF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x4f5cx8005x7248x6743x6240x6709 x8bf7x5c0ax91cdx5e76x4f7fx7528x6b63x7248
FileVersion: 1.0.0.0
Comments: x90d1x5ddex706bx84ddx7ecfx9500x5546x8fdbx8d27x7cfbx7edf
ProductName: x90d1x5ddex706bx84ddx7ecfx9500x5546x8fdbx8d27x7cfbx7edf
ProductVersion: 1.0.0.0
FileDescription: x90d1x5ddex706bx84ddx7ecfx9500x5546x8fdbx8d27x7cfbx7edf
Translation: 0x0804 0x04b0

Generic PUA MH (PUA) also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.33554774
McAfeeArtemis!090064BEE734
CylanceUnsafe
AegisLabTrojan.Win32.Generic.lpDo
K7AntiVirusTrojan ( 005246d51 )
BitDefenderTrojan.GenericKD.33554774
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.460de1
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Zusy-6840460-0
GDataTrojan.GenericKD.33554774
RisingPUA.Presenoker!8.F608 (CLOUD)
Ad-AwareTrojan.GenericKD.33554774
SophosGeneric PUA MH (PUA)
ComodoWorm.Win32.Dropper.RA@1qraug
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.090064bee7343cdd
EmsisoftTrojan.GenericKD.33554774 (B)
eGambitUnsafe.AI_Score_99%
Antiy-AVLGrayWare/Win32.Presenoker
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D2000156
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34100.@t0@aeYBldfb
MAXmalware (ai score=82)
VBA32BScope.Trojan.Tiggre
ESET-NOD32a variant of Win32/Packed.BlackMoon.A potentially unwanted
YandexRiskware.BlackMoon!
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.73875085.susgen
FortinetW32/Generic_PUA_MH
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Generic PUA MH (PUA)?

Generic PUA MH (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment