Malware

How to remove “Downloader.Win32.Yantai.gbt”?

Malware Removal

The Downloader.Win32.Yantai.gbt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.Yantai.gbt virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Presents an Authenticode digital signature
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Anomalous binary characteristics

Related domains:

update1.bskrt.com
time.bskrt.com
i.bskrt.com
xzqlog.bskrt.com

How to determine Downloader.Win32.Yantai.gbt?


File Info:

crc32: 18A0A99D
md5: 7d153606f4220ad10fb33407a6a1e8fb
name: teamviewer__________________________________________________________________________________________
sha1: ba3c6fa16a4ca0238a5373c281504c685bf32a07
sha256: e0fa7a19e42e0d78dca623afec928cae53a40704886bf38326dd22cba92db9d8
sha512: 41c6cfb0744f4acb02d0512cfa6b18dbfaffb6902f7f9113b3ed346e782bdf1880b6efa4f31e228667a2a2afc0584fad39950b96d7dc997df87db22d84374e24
ssdeep: 24576:QBkX8AWseDUm5jYPkPct++SzE5dq8emKPRXgetWpl/7QPTQV2/K0TZ1ededj:FX8jDUfPsc4+Szg75g2/yQVoVEdedj
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Downloader.Win32.Yantai.gbt also known as:

DrWebProgram.DownLoader.9
CAT-QuickHealPUA.PresenokerRI.S9338388
McAfeeArtemis!7D153606F422
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan-Downloader ( 0054ead51 )
TrendMicroPUA.Win32.Yantai.AD
SymantecPUA.Downloader
Paloaltogeneric.ml
Kasperskynot-a-virus:Downloader.Win32.Yantai.gbt
AlibabaDownloader:Win32/Yantai.7d7e0119
ViRobotTrojan.Win32.Z.Agent.1789728
AegisLabRiskware.Win32.Yantai.1!c
SophosGeneric PUA LK (PUA)
ComodoApplicUnwnt@#3w4o1rwufs38e
F-SecureTrojan.TR/Crypt.ULPM.Gen
ZillyaTrojan.Downloader.Win32.254
Invinceaheuristic
McAfee-GW-EditionArtemis!Trojan
IkarusTrojan.Crypt
CyrenW32/Trojan.MEZP-0337
JiangminDownloader.Yantai.gs
MaxSecureTrojan.Malware.74718695.susgen
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=99)
Endgamemalicious (moderate confidence)
ZoneAlarmnot-a-virus:Downloader.Win32.Yantai.gbt
MicrosoftPUA:Win32/Presenoker
AhnLab-V3Malware/Win32.RL_Generic.R296995
VBA32BScope.Adware.Presenoker
ALYacTrojan.GenericKD.42282210
MalwarebytesTrojan.Downloader
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Downloader.Yantai.AA potentially unsafe
TrendMicro-HouseCallPUA.Win32.Yantai.AD
RisingTrojan.Conteban!8.10C02 (C64:YzY0OmJmdVULAx8m)
YandexTrojan.ULPM!zjXJsv9N2HA
FortinetRiskware/Yantai
WebrootW32.Trojan.Gen
AVGWin32:DropperX-gen [Drp]
AvastWin32:DropperX-gen [Drp]

How to remove Downloader.Win32.Yantai.gbt?

Downloader.Win32.Yantai.gbt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment