PUA

PUA:Win32/UltraDownloads removal tips

Malware Removal

The PUA:Win32/UltraDownloads is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/UltraDownloads virus can do?

  • Creates RWX memory
  • Network activity detected but not expressed in API logs

How to determine PUA:Win32/UltraDownloads?


File Info:

crc32: 51EF817E
md5: 8123ea209ed2f088a3d602b30afeaead
name: 8123EA209ED2F088A3D602B30AFEAEAD.mlw
sha1: 4b5227496a3684c8a1e5a7c51add05cc894243be
sha256: f91567a8b6e3ed5aea72a3b61a57a78c0b1de933a84ee55f7ed18949e170dbea
sha512: e0da2970ad004707e87e8ac2bcab392d6a285ad3a94fbbf48a22f54737ca25d7e5dd085dc9b26b6bb2ffed65b0bcb17219ac1e4145f5f94268aeb25eef82b545
ssdeep: 768:HT8CC3Das6YbXCxWzyQC9oV48QfGLW6/uIJSS:HQCWDLbXNAoTQfGLWLS
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: tlc.exe
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename: tlc.exe

PUA:Win32/UltraDownloads also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSIL.Lynx.18
Qihoo-360Generic/Trojan.9a1
ALYacGen:Variant.MSIL.Lynx.18
CylanceUnsafe
ZillyaAdware.BrowseFox.Win32.282408
SangforMalware
K7AntiVirusTrojan ( 004dbd4e1 )
BitDefenderGen:Variant.MSIL.Lynx.18
K7GWTrojan ( 004dbd4e1 )
Cybereasonmalicious.09ed2f
CyrenW32/MSIL_Lynx.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.MSIL.Tpyn.gen
AlibabaTrojan:MSIL/Injector.9296b0d4
NANO-AntivirusTrojan.Win32.TrjGen.ecykzu
AegisLabTrojan.MSIL.Generic.4!c
Ad-AwareGen:Variant.MSIL.Lynx.18
EmsisoftGen:Variant.MSIL.Lynx.18 (B)
ComodoTrojWare.MSIL.Agent.DEQ@6b1qes
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen6.57728
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.mm
FireEyeGeneric.mg.8123ea209ed2f088
SophosMal/Generic-S + Mal/Kryptik-AD
IkarusTrojan.MSIL.CryptoObfuscator
JiangminTrojan.MSIL.cfih
AviraTR/Dropper.Gen
Antiy-AVLTrojan/MSIL.Tpyn
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftPUA:Win32/UltraDownloads
ArcabitTrojan.MSIL.Lynx.18
SUPERAntiSpywareTrojan.Agent/Gen-Malagent
ZoneAlarmHEUR:Trojan.MSIL.Tpyn.gen
GDataGen:Variant.MSIL.Lynx.18
CynetMalicious (score: 90)
AhnLab-V3Trojan/Win32.Injector.R288829
McAfeeTrojan-FHYP!8123EA209ED2
MAXmalware (ai score=82)
VBA32TrojanDownloader.MSIL.Agent
MalwarebytesTrojan.Dropper.MSIL
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Injector.QJL
TencentMsil.Trojan.Tpyn.Dwsp
YandexTrojan.Tpyn!oKR75zBTswU
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Kryptik.EWB!tr
BitDefenderThetaGen:NN.ZemsilF.34804.bm0@aKaENec
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove PUA:Win32/UltraDownloads?

PUA:Win32/UltraDownloads removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment