PUA

Generic PUA NE (PUA) removal tips

Malware Removal

The Generic PUA NE (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA NE (PUA) virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic PUA NE (PUA)?


File Info:

crc32: 8A1EA650
md5: 667d205e2ab6177c6c677f991d507fb0
name: upload_file
sha1: d4701dd9cf410dae37dc0328cdc4cb1a5353621b
sha256: 8333ba5146dd7f8dde824afe13e0bf988566027dbfcf239f06fd709115db68d7
sha512: 2337cfe5666d1f053a9aee2d9c5a29ffd4671c9a418d6a91eece922be3e5d482bbb1118bd9186b8d9ed84804934e9bf235f45dc460511516a7c6f0996e5b85fb
ssdeep: 12288:sOZlAvXBW34aSHxF5en1PwGP0eAMNzVn2Vd13Ude/T:dlUM4aSHTUn1PQeLNzV2H17/T
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Gladis NDOUAB'S
InternalName:
FileVersion: 1.1.4.9
CompanyName: NDSoft Corp
LegalTrademarks:
Comments: gndouabs@hotmail.de
ProductName: LockDisk
ProductVersion: 1.0.0.0
FileDescription: Interdire (Bloquer) un CD/DVD sur votre ordinateur
OriginalFilename:
Translation: 0x040c 0x04e4

Generic PUA NE (PUA) also known as:

MicroWorld-eScanTrojan.GenericKD.44055467
FireEyeGeneric.mg.667d205e2ab6177c
McAfeeArtemis!667D205E2AB6
MalwarebytesTrojan.Injector
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan-Downloader ( 00570e8d1 )
BitDefenderTrojan.GenericKD.44055467
K7GWTrojan-Downloader ( 00570e8d1 )
InvinceaGeneric PUA NE (PUA)
CyrenW32/Trojan.OWVW-2989
SymantecTrojan Horse
APEXMalicious
AvastWin32:InjectorX-gen [Trj]
KasperskyHEUR:HackTool.Win32.Agent.gen
AlibabaTrojanDownloader:Win32/fekpp.92dd3061
Ad-AwareTrojan.GenericKD.44055467
EmsisoftTrojan.GenericKD.44055467 (B)
F-SecureTrojan.TR/Dldr.Delf.fekpp
DrWebTrojan.Siggen10.36912
TrendMicroTrojan.Win32.ZYX.USMANJD20
McAfee-GW-EditionRDN/Generic PUP.z
SophosGeneric PUA NE (PUA)
JiangminHackTool.Agent.doh
eGambitPE.Heur.InvalidSig
AviraTR/Dldr.Delf.fekpp
MAXmalware (ai score=81)
MicrosoftTrojan:Win32/Woreflint.A!cl
ArcabitTrojan.Generic.D2A03BAB
ZoneAlarmHEUR:HackTool.Win32.Agent.gen
GDataWin32.Trojan.PSE.19AUM4N
CynetMalicious (score: 90)
ALYacTrojan.GenericKD.44055467
PandaTrj/GdSda.A
ESET-NOD32Win32/TrojanDownloader.Delf.DAZ
TrendMicro-HouseCallTrojan.Win32.ZYX.USMANJD20
RisingDownloader.Delf!8.16F (TFE:4:ZZegk5sEAeI)
IkarusTrojan-Spy.LokiBot
FortinetRiskware/Agent.DAZ!tr.dldr
WebrootW32.Trojan.Gen
AVGWin32:InjectorX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.fba

How to remove Generic PUA NE (PUA)?

Generic PUA NE (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment