PUA

About “Potentially Unwanted Software (PUA)” infection

Malware Removal

The Potentially Unwanted Software (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Potentially Unwanted Software (PUA) virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (11 unique times)
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Steals private information from local Internet browsers
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
mininews.kpzip.com
kyposition.dftoutiao.com
mini2.eastday.com
mini.7654.com
hotnews.dftoutiao.com
afpmm.alicdn.com
www.nkscdn.com
tajs.qq.com
ocsp.digicert.com
hm.baidu.com

How to determine Potentially Unwanted Software (PUA)?


File Info:

crc32: 559BF747
md5: ade41edb6efd11f58994086e4d3f2e35
name: mininews-1.exe
sha1: 0b342eb683fe8b15719d943f0805c91f1f15cc96
sha256: f4e9528980db86760a247b1153b4b2d5034a4ec370a73ee702723c0705fbbd70
sha512: 2075c27076dbd3257224fcadf23cfb80453dcfbf48b361ac95afea472dd207aa96bcc3f264d33898491424cde9de0103d7b7d7e9d258dc053e850622a40b7f91
ssdeep: 49152:xvUw2jZwO51+cow/3aDZfm6UOlxIjreSkLRAa+:Sw7O51+coTDdUOlxIj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2010-2018
ProductVersion: 2018.12.14.1
FileVersion: 2018.12.14.1
FileDescription: x540ax5170x5febx8baf
Translation: 0x0804 0x04b0

Potentially Unwanted Software (PUA) also known as:

BkavW32.HfsAdware.C51A
MicroWorld-eScanGen:Variant.Application.Strictor.172413
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeePUP-XGX-RZ
CylanceUnsafe
ZillyaAdware.KuaiZip.Win32.131
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Application.Strictor.172413
K7GWAdware ( 004f7e1c1 )
K7AntiVirusAdware ( 004f7e1c1 )
TrendMicroTROJ_GEN.R002C0PC920
F-ProtW32/S-0bbf5fa1!Eldorado
SymantecAdware.Adpopup
ESET-NOD32a variant of Win32/KuaiZip.B potentially unwanted
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
Kasperskynot-a-virus:HEUR:AdWare.Win32.KuziTui.gen
AlibabaBackdoor:Win32/KZip.a3d76147
NANO-AntivirusRiskware.Win32.KuaiZip.flnsyw
Ad-AwareGen:Variant.Application.Strictor.172413
EmsisoftGen:Variant.Application.Strictor.172413 (B)
ComodoApplicUnwnt@#2ms9nhpynqdy8
F-SecurePotentialRisk.PUA/KuaiZip.Gen
DrWebProgram.Kuaizip.1
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionPUP-XGX-RZ
FireEyeGeneric.mg.ade41edb6efd11f5
SophosPotentially Unwanted Software (PUA)
CyrenW32/S-0bbf5fa1!Eldorado
JiangminAdWare.KuaiZip.cr
MaxSecureTrojan.Malware.73580967.susgen
AviraPUA/KuaiZip.Gen
FortinetRiskware/KuaiZip
Antiy-AVLGrayWare[AdWare]/Win32.KuaiZip
Endgamemalicious (high confidence)
ArcabitTrojan.Application.Strictor.D2A17D
SUPERAntiSpywarePUP.KuaiZip/Variant
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.KuziTui.gen
MicrosoftPUA:Win32/KuaiZip
AhnLab-V3PUP/Win32.KuaiZip.R251660
MAXmalware (ai score=100)
VBA32BScope.Adware.KuaiZip
MalwarebytesAdware.Kuaiba
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PC920
TencentMalware.Win32.Gencirc.10ba440a
YandexPUA.KuaiZip!
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
GDataGen:Variant.Application.Strictor.172413
AVGWin32:AdwareX-gen [Adw]
Cybereasonmalicious.b6efd1

How to remove Potentially Unwanted Software (PUA)?

Potentially Unwanted Software (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment