PUA

Generic PUA LK (PUA) removal tips

Malware Removal

The Generic PUA LK (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic PUA LK (PUA) virus can do?

  • Presents an Authenticode digital signature
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (5 unique times)
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Anomalous binary characteristics

Related domains:

update1.bskrt.com
myip.ipip.net
time.bskrt.com
dl.ttp1.cn
i.bskrt.com
xzqlog.bskrt.com

How to determine Generic PUA LK (PUA)?


File Info:

crc32: 18A0A99D
md5: 7d153606f4220ad10fb33407a6a1e8fb
name: teamviewer__________________________________________________________________________________________
sha1: ba3c6fa16a4ca0238a5373c281504c685bf32a07
sha256: e0fa7a19e42e0d78dca623afec928cae53a40704886bf38326dd22cba92db9d8
sha512: 41c6cfb0744f4acb02d0512cfa6b18dbfaffb6902f7f9113b3ed346e782bdf1880b6efa4f31e228667a2a2afc0584fad39950b96d7dc997df87db22d84374e24
ssdeep: 24576:QBkX8AWseDUm5jYPkPct++SzE5dq8emKPRXgetWpl/7QPTQV2/K0TZ1ededj:FX8jDUfPsc4+Szg75g2/yQVoVEdedj
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generic PUA LK (PUA) also known as:

DrWebProgram.DownLoader.9
CAT-QuickHealPUA.PresenokerRI.S9338388
McAfeeArtemis!7D153606F422
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan-Downloader ( 0054ead51 )
TrendMicroPUA.Win32.Yantai.AD
SymantecPUA.Downloader
Paloaltogeneric.ml
Kasperskynot-a-virus:Downloader.Win32.Yantai.gbt
AlibabaDownloader:Win32/Yantai.7d7e0119
ViRobotTrojan.Win32.Z.Agent.1789728
AegisLabRiskware.Win32.Yantai.1!c
SophosGeneric PUA LK (PUA)
ComodoApplicUnwnt@#3w4o1rwufs38e
F-SecureTrojan.TR/Crypt.ULPM.Gen
ZillyaTrojan.Downloader.Win32.254
Invinceaheuristic
McAfee-GW-EditionArtemis!Trojan
IkarusTrojan.Crypt
CyrenW32/Trojan.MEZP-0337
JiangminDownloader.Yantai.gs
MaxSecureTrojan.Malware.74718695.susgen
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=99)
Endgamemalicious (moderate confidence)
ZoneAlarmnot-a-virus:Downloader.Win32.Yantai.gbt
MicrosoftPUA:Win32/Presenoker
AhnLab-V3Malware/Win32.RL_Generic.R296995
VBA32BScope.Adware.Presenoker
ALYacTrojan.GenericKD.42282210
MalwarebytesTrojan.Downloader
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Downloader.Yantai.AA potentially unsafe
TrendMicro-HouseCallPUA.Win32.Yantai.AD
RisingTrojan.Conteban!8.10C02 (C64:YzY0OmJmdVULAx8m)
YandexTrojan.ULPM!zjXJsv9N2HA
FortinetRiskware/Yantai
WebrootW32.Trojan.Gen
AVGWin32:DropperX-gen [Drp]
AvastWin32:DropperX-gen [Drp]

How to remove Generic PUA LK (PUA)?

Generic PUA LK (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment