PUA

About “PUA.Reimagelim.Gen” infection

Malware Removal

The PUA.Reimagelim.Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.Reimagelim.Gen virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Uses Windows utilities to enumerate running processes
  • Uses Windows utilities for basic functionality
  • Queries information on disks, possibly for anti-virtualization
  • Detects Bochs through the presence of a registry key
  • Attempted to write directly to a physical drive
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine PUA.Reimagelim.Gen?


File Info:

name: F17F454BBD6DA44DA5F0.mlw
path: /opt/CAPEv2/storage/binaries/586d6d00ca3df6e51c50c8ee6ae01b6d489683bab5c8ba2e18c24a0c21fd482f
crc32: 0175CDEC
md5: f17f454bbd6da44da5f03eca04d2302d
sha1: 04c38bd087fddc5f97617b9b4a0fc9120df071d8
sha256: 586d6d00ca3df6e51c50c8ee6ae01b6d489683bab5c8ba2e18c24a0c21fd482f
sha512: d4d130abc1fcc2fa37391a0577defaa16b899ca38abf9321ef8880655df0e3970eea22d6a163e6bf54ab675ea654239f96a11fe91538d91bce49a96d0783db87
ssdeep: 1536:NGarUa6LowvuhdNYh2Gf9rg6hzGPnqiUas16R7Wl2zZj5sxtzwGgKn4HzQaNb/kc:z5BuYAVrgUCPn3nZ80ZKCz/J/73d0SOS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BFB3BF866EE49036FABB1EF01AB5B65345FABF101C75CA1BA314BDCD3930B414A28717
sha3_384: e22eecd8364a272c666eef3ac99d29c4fb05b79b565e4a7b6c802a1626d38857b2f71727f5804545552862190fcacc68
ep_bytes: 81ecd4020000535556576a2033ed5e89
timestamp: 2012-02-24 19:20:04

Version Info:

0: [No Data]

PUA.Reimagelim.Gen also known as:

DrWebProgram.Unwanted.376
CAT-QuickHealPUA.Reimagelim.Gen
ZillyaAdware.Eorezo.Win32.25396
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/ReImageRepair.K potentially unwanted
APEXMalicious
AvastWin32:Adware-gen [Adw]
TencentTrojan.Win32.BitCoinMiner.la
JiangminHoax.PCRepair.at
MicrosoftPUA:Win32/Reimage
MalwarebytesPUP.Optional.Reimage
eGambitPUP.Optional.Reimage
AVGWin32:Adware-gen [Adw]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove PUA.Reimagelim.Gen?

PUA.Reimagelim.Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment