PUA

Win32:PUPX-gen [PUP] malicious file

Malware Removal

The Win32:PUPX-gen [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:PUPX-gen [PUP] virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)

Related domains:

z.whorecord.xyz
a.tomx.xyz
w.nanweng.cn

How to determine Win32:PUPX-gen [PUP]?


File Info:

crc32: C43DA8D4
md5: f2712b814b394659b33cb2e54584bb37
name: E69AB4E9A38EE5BDB1E99FB352908406_102071.exe
sha1: 912c2c375571adbf02363c63e4df7194f1bd6df0
sha256: 364c9c11abbde852e5d7d29c7e1ce295ba7bd8505178eb737bfb7b4033d7e13a
sha512: e3fd5cc12bd54e34b7aa6251da653591a1ee6309c6da22f6a7ad6890ced01293602714373ca774d8d458c611f2c7b9a889eebfd49a2fdabf15389a23f19e8c9c
ssdeep: 24576:MB+FvOMlXspw7nU6LtEeTR4kBFuHXxW4Z20gZzZVlSzJzndeNUPq+C:MBCqwbdZu3d00oVlSzJ7dep+C
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020
InternalName: x667ax80fdx4e0bx8f7dx5668.exe
FileVersion: 5.0.0.0207
ProductName: x667ax80fdx4e0bx8f7dx5668.exe
ProductVersion: 5.0.0.0207
FileDescription: x667ax80fdx4e0bx8f7dx5668
OriginalFilename: x667ax80fdx4e0bx8f7dx5668.exe
Translation: 0x0804 0x04b0

Win32:PUPX-gen [PUP] also known as:

MicroWorld-eScanGen:Variant.Razy.583593
McAfeeQJWMonkey
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 005105151 )
BitDefenderGen:Variant.Razy.583593
K7GWAdware ( 005105151 )
TrendMicroTROJ_GEN.R002C0PBD20
SymantecTrojan.Gen.9
APEXMalicious
AvastWin32:PUPX-gen [PUP]
GDataGen:Variant.Razy.583593
Kasperskynot-a-virus:HEUR:Downloader.Win32.Generic
AlibabaAdWare:Win32/Qjwmonkey.4e15722a
NANO-AntivirusRiskware.Win32.Qjwmonkey.hamvws
Endgamemalicious (high confidence)
SophosQjMonkey (PUA)
ComodoApplication.Win32.Qjwmonkey.HU@8hjovh
F-SecureHeuristic.HEUR/AGEN.1042852
DrWebAdware.Qjwmonkey.168
Invinceaheuristic
McAfee-GW-EditionQJWMonkey
MaxSecureTrojan.Malware.121218.susgen
FireEyeGeneric.mg.f2712b814b394659
EmsisoftGen:Variant.Razy.583593 (B)
IkarusPUA.Qjwmonkey
CyrenW32/Adware.OBYM-0540
JiangminDownloader.Generic.avgr
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1042852
Antiy-AVLGrayWare[AdWare]/Win32.Qjwmonkey
MicrosoftPUA:Win32/Qjwmonkey
ArcabitTrojan.Razy.D8E7A9
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.Generic
AhnLab-V3PUP/Win32.RL_Qjwmonkey.R287544
VBA32BScope.Adware.Qjwmonkey
ALYacGen:Variant.Razy.583593
MAXmalware (ai score=100)
Ad-AwareGen:Variant.Razy.583593
MalwarebytesAdware.ChinAd
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Adware.Qjwmonkey.H
TrendMicro-HouseCallTROJ_GEN.R002C0PBD20
RisingAdware.Downloader!1.BDCA (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Qjwmonkey.KD!tr
AVGFileRepMalware [PUP]
Cybereasonmalicious.14b394
Paloaltogeneric.ml

How to remove Win32:PUPX-gen [PUP]?

Win32:PUPX-gen [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment