PUA

PUA:Win32/Yantai removal instruction

Malware Removal

The PUA:Win32/Yantai is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/Yantai virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)

Related domains:

z.whorecord.xyz
ht.sulang.com
a.tomx.xyz

How to determine PUA:Win32/Yantai?


File Info:

crc32: 330D5B2D
md5: 83e50859569ea3c27785f77a32a1f775
name: ansys.exe
sha1: c43f6edb15d50f9ecda97826aab280441c8d9c92
sha256: 24647752e6605f3649f726b286d267e1bdf4411989ea1d4229a030cf15a0a159
sha512: 3a0444aceef96116180219bad0526db9c48dc73369619024b3e180316c8968801731cf181dce95bb7ce1b818d609b88d16468f7d65a0f9b3f06fe1bedcaee891
ssdeep: 12288:INIFPCNmW/roIOK5sh7hKahobtecZiMNGMi+YNzzeSZKWeX8zdHg:6IFP0mW/rHOK+h7IbtecIM4Mi+YNzzP8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Downloaderx7248x6743x6240x6709
InternalName: DownLoad.exe
FileVersion: 1.0.0.1
ProductName: Downloaderx5e94x7528x7a0bx5e8f
ProductVersion: 1.0.0.1
FileDescription: Downx3000loader
OriginalFilename: DownLoad.exe
Translation: 0x0804 0x04b0

PUA:Win32/Yantai also known as:

DrWebAdware.ShouQu.41
MicroWorld-eScanGen:Variant.Johnnie.85379
FireEyeGeneric.mg.83e50859569ea3c2
CAT-QuickHealTrojan.IGENERIC
ALYacGen:Variant.Johnnie.85379
MalwarebytesAdware.ChinAd
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 0050fcab1 )
BitDefenderGen:Variant.Johnnie.85379
K7GWAdware ( 0050fcab1 )
Cybereasonmalicious.9569ea
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Adware-gen [Adw]
GDataGen:Variant.Johnnie.85379
AlibabaAdWare:Win32/Xiaoxiong.f0f468ca
NANO-AntivirusRiskware.Win32.Xiaoxiong.eoblsj
RisingMalware.Generic.5!tfe (CLOUD)
Ad-AwareGen:Variant.Johnnie.85379
SophosGeneric PUA ME (PUA)
ComodoApplication.Win32.Xiaoxiong.AD@6ln25d
F-SecureHeuristic.HEUR/AGEN.1016616
ZillyaAdware.XiaoxiongCRTD.Win32.11454
TrendMicroHT_XIAOXIONG_GD210040.UVPM
McAfee-GW-EditionPUP-XCG-LO
EmsisoftGen:Variant.Johnnie.85379 (B)
IkarusPUA.Xiaoxiong
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1016616
Antiy-AVLTrojan/Win32.TSGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.Johnnie.D14D83
MicrosoftPUA:Win32/Yantai
AhnLab-V3PUP/Win32.Helper.R198813
McAfeePUP-XCG-LO
MAXmalware (ai score=99)
VBA32BScope.Adware.ShouQu
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Adware.Xiaoxiong.C
TrendMicro-HouseCallHT_XIAOXIONG_GD210040.UVPM
TencentWin32.Trojan.Zusy.Ecan
YandexPUA.Xiaoxiong!
SentinelOneDFI – Suspicious PE
eGambitGeneric.Adware
FortinetRiskware/Xiaoxiong
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (D)
MaxSecureTrojan.Malware.10758686.susgen

How to remove PUA:Win32/Yantai?

PUA:Win32/Yantai removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment