PUA

How to remove “Win64:PUP-gen [PUP]”?

Malware Removal

The Win64:PUP-gen [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64:PUP-gen [PUP] virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

jq.qq.com
www.bing.com
ocsp.dcocsp.cn
qm.qq.com

How to determine Win64:PUP-gen [PUP]?


File Info:

crc32: 6A6410DA
md5: e89d858f8b9cf41e090c446513a79138
name: salikhac.exe
sha1: ee899c233da667985eb6dcc3023d7d80e7384687
sha256: b908c4c07042d2b4045ce0c67a32a7025a7b851567dfcf84e4b53adfb66cf282
sha512: dc0efd00b9f113068ecf1fe07e62dfff052c24430681e6b4f63e56456e191f4b882e4d6a843ce14aa0b7405d5cb830c8fb27dd52613e3610cb417472fbc3aed5
ssdeep: 49152:UJQwMhbAblJ/06JtTKIxFtA4y5uJ/mKc1CivG3cVXcYz7NWu22wS3BNM:WQwMhbAblJ/06JtTKIxFtA4y5uJ/vc1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x672cx8f6fx4ef6x4ec5x4f9bx4ea4x6d41x5b66x4e60xff0cx8bf7x5728x4e0bx8f7dx540e24x5c0fx65f6x5185x5220x9664x3002
FileVersion: 1.0.0.0
CompanyName: Loser
Comments: x672cx8f6fx4ef6x4ec5x4f9bx4ea4x6d41x5b66x4e60xff0cx8bf7x5728x4e0bx8f7dx540e24x5c0fx65f6x5185x5220x9664x3002
ProductName: x6ca1x540d
ProductVersion: 1.0.0.0
FileDescription: QQx7fa41095630435
Translation: 0x0804 0x04b0

Win64:PUP-gen [PUP] also known as:

BkavW32.HfsAutoB.
DrWebTrojan.Rootkit.22087
MicroWorld-eScanTrojan.GenericKD.33741319
McAfeeArtemis!E89D858F8B9C
CylanceUnsafe
SangforMalware
K7AntiVirusAdware ( 005071f51 )
BitDefenderTrojan.GenericKD.33741319
K7GWAdware ( 005071f51 )
CrowdStrikewin/malicious_confidence_70% (W)
ArcabitTrojan.Generic.D202DA07
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34108.5v1@aqjha!jb
F-ProtW32/Agent.EW.gen!Eldorado
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002H0CDT20
Paloaltogeneric.ml
ClamAVWin.Malware.Gotango-7000352-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/Wannaren.b576d936
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
ViRobotTrojan.Win32.Z.Agent.1990071
AegisLabTrojan.Win32.Poison.kYJP
RisingTrojan.Generic!8.C3 (CLOUD)
Ad-AwareTrojan.GenericKD.33741319
EmsisoftTrojan.GenericKD.33741319 (B)
ComodoBackdoor.Win32.SkSocket.AD@5t7qie
F-SecureTrojan.TR/Crypt.XPACK.Gen
McAfee-GW-EditionBehavesLike.Win32.Generic.th
FortinetRiskware/Generic
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.e89d858f8b9cf41e
SophosGeneric PUA OO (PUA)
IkarusTrojan.Win32.Antavmu
CyrenW32/Agent.EW.gen!Eldorado
MAXmalware (ai score=86)
Antiy-AVLGrayWare/Win32.FlyStudio.a
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Occamy.C
ZoneAlarmHEUR:Trojan.Win32.Generic
AhnLab-V3Trojan/Win32.Black.R135897
Acronissuspicious
VBA32BScope.Trojan.Downloader
ALYacTrojan.GenericKD.33741319
APEXMalicious
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
GDataTrojan.GenericKD.33741319
AVGWin64:PUP-gen [PUP]
AvastWin64:PUP-gen [PUP]
Qihoo-360Generic/HEUR/QVM19.1.DF24.Malware.Gen

How to remove Win64:PUP-gen [PUP]?

Win64:PUP-gen [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment