PUA

Should I remove “PUA.IgenericRI.S10596407”?

Malware Removal

The PUA.IgenericRI.S10596407 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.IgenericRI.S10596407 virus can do?

  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity contains more than one unique useragent.
  • Generates some ICMP traffic

Related domains:

api.pcsoft.jshhdian.com
ggstats.yb.jshhdian.com
eoud.dgygpx.com
www.baidu.com
api.yb.jshhdian.com
poik.dgygpx.com
ymte.sgdebao.com
dw.jshhdian.com
api.pcsoft.70gj.cn
s13.cnzz.com
ocsp.globalsign.com
ocsp2.globalsign.com
z7.cnzz.com
c.cnzz.com
cnzz.mmstat.com

How to determine PUA.IgenericRI.S10596407?


File Info:

crc32: 3A420A53
md5: 06b3fbfac20e62ba968d10681da4c3ef
name: ___________________24_238.exe
sha1: f0412da63390dd278127fe2927b7eb5825ae4dcf
sha256: 1137c68493061a7dd62363cb849b2a7b442d776e2ae0187ba4be0d6c54d9d784
sha512: ff9a6210a3c3e65fb45ef2e405a159284f582525ff986f3cacf806bdc611a5dca049447658ff7ef504de1bee6835fb0f66217a2cad5bce9d3c3766e25e441189
ssdeep: 98304:7djrfbWvOUlCnJ+I9P0ABLGejAMJ8C2IXDOXqHBQ+RSQnhj1Emq3v05hX6mx3o19:dCO0E0ABLlJfCQjqX3vU3IrftzUM
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2019
FileVersion: 3.0.1.2
ProductName: x6781x901fx4e0bx8f7dx5668
ProductVersion: 3.0.1.2
FileDescription: x6781x901fx4e0bx8f7dx5668
OriginalFilename: Install.exe
Translation: 0x0804 0x03a8

PUA.IgenericRI.S10596407 also known as:

MicroWorld-eScanTrojan.GenericKD.42284019
FireEyeGeneric.mg.06b3fbfac20e62ba
CAT-QuickHealPUA.IgenericRI.S10596407
McAfeeGenericRXAA-AA!06B3FBFAC20E
ZillyaTool.YouXun.Win32.803
K7AntiVirusRiskware ( 0050b49d1 )
BitDefenderTrojan.GenericKD.42284019
K7GWRiskware ( 0050b49d1 )
Cybereasonmalicious.63390d
BitDefenderThetaGen:NN.ZexaF.34084.@pLfaqRCqwnj
F-ProtW32/S-d8efc1c1!Eldorado
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.GenericKD.42284019
Kasperskynot-a-virus:HEUR:Downloader.Win32.YXdown.pef
Endgamemalicious (moderate confidence)
EmsisoftTrojan.GenericKD.42284019 (B)
F-SecurePrivacyRisk.SPR/GameTool.Gen8
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
Trapminesuspicious.low.ml.score
IkarusPUA.RiskWare.Youxun
CyrenW32/S-d8efc1c1!Eldorado
JiangminDownloader.YXdown.bz
MaxSecureTrojan.Malware.74721109.susgen
AviraSPR/GameTool.Gen8
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Wacatac.D!ml
ArcabitTrojan.Generic.D28533F3
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.YXdown.pef
AhnLab-V3Malware/Win32.Generic.C3974891
VBA32Downloader.YXdown
ALYacTrojan.GenericKD.42284019
Ad-AwareTrojan.GenericKD.42284019
MalwarebytesRiskWare.YouXun
ESET-NOD32a variant of Win32/RiskWare.YouXun.H
RisingAdware.Downloader!1.B962 (RDMK:cmRtazqNJNepVcp8MfFXEqb69QTV)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/GenericKD.32784984!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_80% (D)

How to remove PUA.IgenericRI.S10596407?

PUA.IgenericRI.S10596407 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment