PUA

PUA:Win32/Ushendu removal

Malware Removal

The PUA:Win32/Ushendu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/Ushendu virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine PUA:Win32/Ushendu?


File Info:

crc32: 8988ED05
md5: c78f2e8534c4963d8f9055861f0708db
name: C78F2E8534C4963D8F9055861F0708DB.mlw
sha1: 064dc9c167451c711e26f9b0f3c88d3b6c644c79
sha256: de8656f7b965a04fcff690c98dbbe135f74520ff9067cce024078bdd9a4ebdde
sha512: e51a0e55deff68642e5c7c03dbc3075a3c9b044d6e5beb4e04be439f246b2ffc5f257bfef9dbc243f37a78a020d2adfe92591a6fa6d464a63e2b640bc07d3372
ssdeep: 49152:xUTsamYxUa2ZK/m0W90oi0piAKjDgJG8V1UsbHToWL1OU:xaHUDKe0W90oVkXDgH1UkTtL1H
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: (C) UQiDong.Com All Rights Reserved.
FileVersion: 7.0.16.712
CompanyName: UQiDong.Com
Comments: UQiDong.Com
ProductName: Ux542fx52a8x88c5x673ax7248x5b89x88c5x7a0bx5e8f
ProductVersion: 7.0.16.712
FileDescription: Ux542fx52a8x88c5x673ax7248x5b89x88c5x7a0bx5e8f
Translation: 0x0804 0x04b0

PUA:Win32/Ushendu also known as:

MicroWorld-eScanAIT:Trojan.Nymeria.4316
FireEyeGeneric.mg.c78f2e8534c4963d
McAfeeArtemis!C78F2E8534C4
CylanceUnsafe
AegisLabTrojan.Win32.Nymeria.4!c
SangforPUP.Win32.Ushendu.mt
K7AntiVirusTrojan ( 700000111 )
BitDefenderAIT:Trojan.Nymeria.4316
K7GWTrojan ( 700000111 )
SymantecML.Attribute.HighConfidence
APEXMalicious
RisingAdware.OpenUrl/Autoit!1.C4BD (CLASSIC)
Ad-AwareAIT:Trojan.Nymeria.4316
EmsisoftAIT:Trojan.Nymeria.4316 (B)
F-SecureHeuristic.HEUR/AGEN.1102725
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.vc
SophosGeneric PUA AG (PUA)
IkarusTrojan.Jord
AviraHEUR/AGEN.1102725
MAXmalware (ai score=81)
Antiy-AVLGrayWare/Autoit.BinToStr.a
MicrosoftPUA:Win32/Ushendu
GridinsoftTrojan.Win32.Downloader.oa
ArcabitAIT:Trojan.Nymeria.D10DC
GDataAIT:Trojan.Nymeria.4316 (3x)
CynetMalicious (score: 90)
ALYacAIT:Trojan.Nymeria.4316
MalwarebytesMalware.AI.3957223602
ESET-NOD32a variant of Win32/UShenDu.A potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002H09B421
eGambitUnsafe.AI_Score_100%
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.Loda.HgIASOYA

How to remove PUA:Win32/Ushendu?

PUA:Win32/Ushendu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment