PUA

PUA.Xacti.Gen (file analysis)

Malware Removal

The PUA.Xacti.Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA.Xacti.Gen virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine PUA.Xacti.Gen?


File Info:

name: 082000CAA1B36B45F4D5.mlw
path: /opt/CAPEv2/storage/binaries/24fc422425ecde78ee3d930e5ebd13d3889648eade91513c60265651b2e2ac9c
crc32: 6EE044BA
md5: 082000caa1b36b45f4d536a733a23d46
sha1: 9bf46e680daf37b29fc2642c3c52bdf424c2d28f
sha256: 24fc422425ecde78ee3d930e5ebd13d3889648eade91513c60265651b2e2ac9c
sha512: 1eee91655d418ab7dd776da98bc7d04f35473c5510335824c6864853d12805d90e5b304b6a2a712ca3655f269eabd0b4806804800dac3b180f9ccdd11281649a
ssdeep: 24576:nmdW7w83t6Wea8u0105qwD7Xw9FiLDuC0vOoVSIgHNnvExCc:nBwZ05qXqdEfgNNQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A3458E32F2918437D4731B785D1BD3D8583ABE203E24A8977BF91E4C5F39681792A293
sha3_384: 85444c8128643274e1eb8441fcb3c439ee4d23b228884bb2e98eca4db7ea13e350e527b893e48b60aac4ae43752c3687
ep_bytes: 558bec83c4f0535657b818934f00e8a9
timestamp: 2012-12-20 13:23:26

Version Info:

FileDescription: Setup/Uninstall
FileVersion: 51.51.0.0
Translation: 0x0000 0x04b0

PUA.Xacti.Gen also known as:

LionicRiskware.Win32.Generic.1!c
CAT-QuickHealPUA.Xacti.Gen
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
SymantecPUA.InboxToolbar
TrendMicro-HouseCallTROJ_GEN.R002H05L521
ClamAVWin.Adware.Toolbar-6606401-0
SophosGeneric PUA JL (PUA)
McAfee-GW-EditionBehavesLike.Win32.BadFile.th
JiangminWebToolbar.MusIn.y
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.B61218
GridinsoftRansom.Win32.Sabsik.sa
CynetMalicious (score: 100)
McAfeeArtemis!082000CAA1B3
FortinetRiskware/Toolbar

How to remove PUA.Xacti.Gen?

PUA.Xacti.Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment