Categories: PUA

Generic PUA PC (PUA) removal guide

The Generic PUA PC (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA PC (PUA) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it

Related domains:

z.whorecord.xyz
a.tomx.xyz
reqbus.ru
ssl.google-analytics.com

How to determine Generic PUA PC (PUA)?


File Info:

crc32: A684766Emd5: bfcd45d6539c965f7502ba9805af65a3name: processhacker-setup.exesha1: f21be5ca9139dfee2179e72f3d7b3ef03ad62704sha256: 5fb3a435700784da1a4789468cc4aadb6752ec63a73434509075d556e4a939cesha512: da4b9603a5adb08df4efc79699b0576873ba388c6bc41c839787b080a6258ddd27a2b44a5b9cef48eadffb4487d695c1c0dad713130e4ca267bd96e8e79bb2cessdeep: 196608:4/ULRjVZdLSEvJBWqWmXuZV5otHEdfHo8B3Am62jL:GIjtSExBxTXc+aVAm6Ytype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: FileVersion: CompanyName: Comments: This installation was built with Inno Setup.ProductName: Process Hacker 2.39 ProductVersion: FileDescription: Process Hacker 2.39 Setup (r18) Translation: 0x0000 0x04b0

Generic PUA PC (PUA) also known as:

Bkav W32.AIDetectVM.malware
McAfee Artemis!BFCD45D6539C
Cylance Unsafe
Symantec ML.Attribute.HighConfidence
Kaspersky not-a-virus:HEUR:RiskTool.Win32.ProcHack.gen
Alibaba RiskWare:Win32/ProcHack.8eaeec77
Paloalto generic.ml
DrWeb Tool.ProcessHacker.3
McAfee-GW-Edition BehavesLike.Win32.Dropper.rc
Sophos Generic PUA PC (PUA)
Cyren W32/Trojan.QASS-1967
Endgame malicious (high confidence)
AegisLab Riskware.Win32.ProcHack.1!c
ZoneAlarm not-a-virus:HEUR:RiskTool.Win32.ProcHack.gen
Microsoft Trojan:Win32/Wacatac.C!ml
Yandex Riskware.ProcessHacker!
Ikarus Trojan-Downloader.Banload
Fortinet Riskware/ProcHack
Qihoo-360 Win32/Virus.RiskTool.f72

How to remove Generic PUA PC (PUA)?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Win32:AutoRun-BSW [Wrm] malicious file

The Win32:AutoRun-BSW [Wrm] is considered dangerous by lots of security experts. When this infection is…

54 mins ago

About “MSIL/TrojanDownloader.Agent.QQN” infection

The MSIL/TrojanDownloader.Agent.QQN is considered dangerous by lots of security experts. When this infection is active,…

59 mins ago

Malware.AI.975225574 removal

The Malware.AI.975225574 is considered dangerous by lots of security experts. When this infection is active,…

59 mins ago

Ursu.840201 (file analysis)

The Ursu.840201 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Should I remove “Malware.AI.4025139158”?

The Malware.AI.4025139158 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Tedy.271097 removal instruction

The Tedy.271097 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago