PUA

PUA.GenericRI.S20175963 removal tips

Malware Removal

The PUA.GenericRI.S20175963 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.GenericRI.S20175963 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Authenticode signature is invalid
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine PUA.GenericRI.S20175963?


File Info:

name: 35185FC96C1AA6F647DC.mlw
path: /opt/CAPEv2/storage/binaries/f01dce417c6b7c72d9a4103a04b05c7aeb876e3b70096e3d4346193e75eb753f
crc32: 5FEEAFD4
md5: 35185fc96c1aa6f647dc9283f4e85339
sha1: 3eb18f80ed75d1bdab7ca9662b3fa6e428cbcfda
sha256: f01dce417c6b7c72d9a4103a04b05c7aeb876e3b70096e3d4346193e75eb753f
sha512: 5b32996c4d80ae0017521572ece9e35217fe516ed24e49211e0298c080777e75a78d2b8405f2e256af31d983475df7adcad436f8aa3c31cb0d869d1494bb4cc9
ssdeep: 96:L9RRsWtkXgqRst25Dts9LV9sAaPtboynunSC1jCt7:LWrs1z+P1oynWSc6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13602B1A9F7A08079F0528BB3C99F732F92544A2DB3A8E495721D60C51D50293D3A17FF
sha3_384: ff6bfddd81e0c2798f292f10914f2930618b7483a252d98c3636835a6730e84b5b5e2e2a9cf14d6805208443c72a946c
ep_bytes: 558bec6aff68a0234000689016400064
timestamp: 2021-04-28 17:17:15

Version Info:

0: [No Data]

PUA.GenericRI.S20175963 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Downloader.auX@a8KQFzmi
CAT-QuickHealPUA.GenericRI.S20175963
McAfeeGenericRXAA-FA!35185FC96C1A
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
K7AntiVirusTrojan ( 0056d4e31 )
AlibabaWorm:Win32/Phorpiex.50bf455e
K7GWTrojan ( 0056d4e31 )
Cybereasonmalicious.96c1aa
CyrenW32/Trojan.RNMJ-0489
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Phorpiex.AG
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Zard-9857815-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Downloader.auX@a8KQFzmi
NANO-AntivirusTrojan.Win32.Phorpiex.iutnzd
AvastWin32:CoinminerX-gen [Trj]
TencentWin32.Trojan.Generic.Lhdg
Ad-AwareGen:Trojan.Downloader.auX@a8KQFzmi
EmsisoftGen:Trojan.Downloader.auX@a8KQFzmi (B)
ComodoTrojWare.Win32.TrojanDownloader.Agent.EQE@80vxxy
F-SecureTrojan.TR/Crypt.XPACK.Gen
ZillyaWorm.Phorpiex.Win32.2229
TrendMicroTROJ_GEN.R002C0GCN22
McAfee-GW-EditionBehavesLike.Win32.Generic.xt
FireEyeGeneric.mg.35185fc96c1aa6f6
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Downloader.auX@a8KQFzmi
JiangminTrojan.Generic.gwhvn
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Phorpiex
KingsoftWin32.Heur.KVMH017.a.(kcloud)
ArcabitTrojan.Downloader.E496E3
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Vigorf.A
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Dlder.C3467007
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34606.auX@a8KQFzmi
ALYacGen:Trojan.Downloader.auX@a8KQFzmi
MAXmalware (ai score=86)
VBA32BScope.Trojan.Sabsik.FL
MalwarebytesWorm.Phorpiex.Generic
TrendMicro-HouseCallTROJ_GEN.R002C0GCN22
RisingWorm.Phorpiex!8.48D (CLOUD)
YandexTrojan.Agent!42/V93Tuuno
IkarusWorm.Win32.Phorpiex
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Phorpiex.AH!worm
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove PUA.GenericRI.S20175963?

PUA.GenericRI.S20175963 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment