PUA

PUA.Generic.12215 removal

Malware Removal

The PUA.Generic.12215 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.Generic.12215 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine PUA.Generic.12215?


File Info:

crc32: 53611D61
md5: 229ae8b86bce422aa9e231f11c85ffeb
name: xinxinmotazhongwenban.exe
sha1: f2edb7315dd436a1cf7349714fc57ab24e5f4326
sha256: bc04dd5cd3a7bdd824bddf60bcc40fcede5823eed723c9140a57b95c40ea8ba7
sha512: a091f21732bb310da1e53e94aa9aef6258680a060cbb52943d5b5e78f4bb2091caa598471428c108e9e3ab21e65bc5145a836f2fc114ee74b789bd0b019d6d97
ssdeep: 98304:xxBte46FN1ZcFIksDmsMrBLTE7GRmmFRzozgVQrHhQxB2RV50dFI7Y2u6C1A:xRgFFcakS9MZo7GmmFRzozgocBe0iY2J
type: PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive

Version Info:

LegalCopyright: (C)
ProductName:
FileVersion:
FileDescription: Producer oylch
Translation: 0x0804 0x04e4

PUA.Generic.12215 also known as:

MicroWorld-eScanAdware.GenericKD.4917125
FireEyeGeneric.mg.229ae8b86bce422a
CAT-QuickHealPUA.Generic.12215
McAfeeArtemis!229AE8B86BCE
MalwarebytesAdware.Kuaiba
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 005524301 )
BitDefenderAdware.GenericKD.4917125
K7GWAdware ( 005524301 )
ArcabitAdware.Generic.D4B0785
BaiduMulti.Threats.InArchive
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/AdWare.Kuaiba.A
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Ramnit-5500
GDataAdware.GenericKD.4917125
Kasperskynot-a-virus:AdWare.Win32.Kuaiba.agm
AlibabaAdWare:Win32/Kuaiba.05e008fd
NANO-AntivirusRiskware.Win32.Kuaiba.efxtnr
ViRobotAdware.Kuaiba.6228337
Ad-AwareAdware.GenericKD.4917125
SophosGeneric PUA KA (PUA)
DrWebTrojan.DownLoader12.389
ZillyaAdware.GenericKD.Win32.4840
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.BadFile.tc
Trapminemalicious.high.ml.score
EmsisoftAdware.GenericKD.4917125 (B)
IkarusPUA.Kuaiba
JiangminAdware/Agent.hxi
WebrootW32.Malware.gen
AviraADWARE/Adware.Gen7
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftPUA:Win32/Bitrepeyp.C
Endgamemalicious (high confidence)
ZoneAlarmnot-a-virus:AdWare.Win32.Kuaiba.agm
ALYacAdware.GenericKD.4917125
VBA32AdWare.Agent
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R061C0WFF19
TencentWin32.Adware.Kuaiba.Hqby
SentinelOneDFI – Suspicious PE
FortinetW32/Agent.BT!tr
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.86bce4
AvastWin32:Adware-gen [Adw]
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360Win32/Virus.Adware.c69

How to remove PUA.Generic.12215?

PUA.Generic.12215 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment