PUA

Generic PUA NI removal instruction

Malware Removal

The Generic PUA NI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA NI virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Generic PUA NI?


File Info:

name: 990ED6FB457B433F34A0.mlw
path: /opt/CAPEv2/storage/binaries/43cf540daf789b15d823559fd2baa4ae9f3a2cb66fb5dde864b073a427521993
crc32: 02982C08
md5: 990ed6fb457b433f34a097cb3afe2277
sha1: d8fff9c0b52f5b6b8f634b609914c70fb20f125f
sha256: 43cf540daf789b15d823559fd2baa4ae9f3a2cb66fb5dde864b073a427521993
sha512: 45fb464dddbb19cdb11c53969bea3874e643721a1c96f67be40fb165f860638700e19b9705bcdceb36db8bd4abf3ef55c72cb67a8e8fccbd2964824e645680ce
ssdeep: 12288:GUVxNcBwaJERwKIMYGN5TYyYkSzkbMPITqqKB:GUVxNUTEyKTYGNRYlkNbMIqVB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T145058D43F58380F6CB24153019F6273A9A35A6450A28DF8BD75ACFB92D72141AE3B35F
sha3_384: ee8a910b0fc4d25bbd21da493a2fe15c76cb4dc20b98971f8786195c67264e82c8a686e96324e63e8603da2f0a7046fa
ep_bytes: 558bec6aff6818484a00687484470064
timestamp: 2018-11-01 05:11:54

Version Info:

0: [No Data]

Generic PUA NI also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.lqH9
Elasticmalicious (high confidence)
FireEyeGeneric.mg.990ed6fb457b433f
CAT-QuickHealRisktool.Flystudio.16886
McAfeeArtemis!990ED6FB457B
CylanceUnsafe
SangforSuspicious.Win32.Save.ins
Cybereasonmalicious.0b52f5
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
Kasperskynot-a-virus:HEUR:RiskTool.Win32.FlyStudio.gen
AvastWin32:Evo-gen [Trj]
ComodoWorm.Win32.Dropper.RA@1qraug
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SophosGeneric PUA NI
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.16DVGAX
Antiy-AVLTrojan/Win32.FlyStudio.a
ViRobotTrojan.Win32.Z.Pse.819200.F
MicrosoftTrojan:Win32/Wacatac.A!ml
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C4293583
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34796.YqW@aK2RWlfb
VBA32BScope.Backdoor.Poison
TrendMicro-HouseCallTROJ_GEN.R002H0CK422
RisingTrojan.Generic@AI.97 (RDML:4c1sj3/BGBosE99X8M5fMQ)
IkarusTrojan-Downloader
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
AVGWin32:Evo-gen [Trj]
PandaTrj/GdSda.A

How to remove Generic PUA NI?

Generic PUA NI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment