PUA

Generic PUA MJ (PUA) malicious file

Malware Removal

The Generic PUA MJ (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA MJ (PUA) virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
yz.app.sogou.com
a.tomx.xyz
ping.t.sogou.com
xz.sogou.com
yze.t.sogou.com

How to determine Generic PUA MJ (PUA)?


File Info:

crc32: D1E51C6A
md5: da5f5c836e9784c0db8596e891313cde
name: sogoucojmb.e
sha1: c98156fadfb0952f609d6ab416a72089da3d6b33
sha256: 3ffd4699a82056ba48e41de570afc1c8bb79ffdc3f7cecb5efe23a675d3ef9a3
sha512: 50f774a28a9739b096ef1d057444e791ca83843f9acfcd85d932c399a75a15b4c6290eaab9a6fc1c711aab6b1a2594a718c9c6841193412709a9dd58239836ec
ssdeep: 49152:JuuE7AnqIxGrGYyZa/tgrYJUGfZC3wA6EylfwEaFW:rE7AqrlyutLxC3sEwwM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2014 Sogou.com Inc. All rights reserved.
InternalName: MiniDownLoad.exe
FileVersion: 3.1.12.94
CompanyName: Sogou.com Inc.
ProductName: x8f6fx4ef6x52a9x624b
ProductVersion: 3.1.12.94
FileDescription: x8f6fx4ef6x52a9x624b
OriginalFilename: MiniDownLoad.exe
Translation: 0x0804 0x04b0

Generic PUA MJ (PUA) also known as:

BkavW32.HfsAdware.170E
FireEyeGeneric.mg.da5f5c836e9784c0
CAT-QuickHealTrojan.MauvaiseRI.S5244821
McAfeePUP-FTL
CylanceUnsafe
ZillyaDownloader.SogouCRTD.Win32.237
SangforMalware
K7AntiVirusUnwanted-Program ( 004cca081 )
K7GWUnwanted-Program ( 004cca081 )
TrendMicroTROJ_GEN.R020C0OKE19
F-ProtW32/Sogou.H.gen!Eldorado
APEXMalicious
ClamAVWin.Worm.Chir-2282
GDataWin32.Trojan.Agent.OSNVMJ
Kasperskynot-a-virus:Downloader.Win32.Sogou.g
AlibabaDownloader:Win32/Sogou.c5197288
NANO-AntivirusTrojan.Win32.Gbot.fgypno
AvastWin32:Malware-gen
EmsisoftApplication.Chindo (A)
ComodoApplication.Win32.Sogou.C@6e9656
F-SecureAdware.ADWARE/Sogou.wqqyp
DrWebBackDoor.Gbot.2850
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Trojan.vc
MaxSecureTrojan.Malware.8608356.susgen
SophosGeneric PUA MJ (PUA)
SentinelOneDFI – Malicious PE
CyrenW32/Sogou.H.gen!Eldorado
AviraADWARE/Sogou.wqqyp
Endgamemalicious (high confidence)
ZoneAlarmnot-a-virus:Downloader.Win32.Sogou.g
MicrosoftPUA:Win32/Sogou
AhnLab-V3PUP/Win32.Downloader.R180775
VBA32Downloader.Sogou
MalwarebytesAdware.Sogou
ESET-NOD32a variant of Win32/Sogou.H potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R020C0OKE19
TencentMalware.Win32.Gencirc.10b135f4
YandexPUA.Downloader!
Ikarusnot-a-virus:Downloader.Sogou
eGambitUnsafe.AI_Score_99%
FortinetRiskware/Sogou
AVGWin32:Malware-gen

How to remove Generic PUA MJ (PUA)?

Generic PUA MJ (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment